CVE-2008-7311
Spree uses a hardcoded hash value
EPSS 1.2%
Description
The session cookie store implementation in Spree 0.2.0 uses a hardcoded `config.action_controller_session` hash value (aka secret key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging an application that contains this value within the `config/environment.rb` file.
How to fix CVE-2008-7311
To remediate CVE-2008-7311, upgrade the affected package to a fixed version below.
- RubyGems/spree—upgrade to 0.4.0 or later
Is CVE-2008-7311 being exploited?
Low — EPSS is 1.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.4.0