CVE-2008-7311

EPSS 0.16%

Spree uses a hardcoded hash value

Published: 5/17/2022Modified: 12/7/2024

Description

The session cookie store implementation in Spree 0.2.0 uses a hardcoded `config.action_controller_session` hash value (aka secret key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging an application that contains this value within the `config/environment.rb` file.

Affected packages (1)

References (8)