CVE-2007-5380
Session fixation vulnerability in Rails
EPSS 3.6%
Description
Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers to hijack web sessions via unspecified vectors related to "URL-based sessions."
How to fix CVE-2007-5380
To remediate CVE-2007-5380, upgrade the affected package to a fixed version below.
- Debian/rails—upgrade to 1.2.5-1 or later
- RubyGems/rails—upgrade to 1.2.4 or later
Is CVE-2007-5380 being exploited?
Low — EPSS is 3.6%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.2.5-1
- from 0, < 1.2.4