CVE-2013-7222
Fat Free CRM has fixed token value
EPSS 2.4%
Description
`config/initializers/secret_token.rb` in Fat Free CRM before 0.12.1 has a fixed `FatFreeCRM::Application.config.secret_token` value, which makes it easier for remote attackers to spoof signed cookies by referring to the key in the source code.
How to fix CVE-2013-7222
To remediate CVE-2013-7222, upgrade the affected package to a fixed version below.
- RubyGems/fat_free_crm—upgrade to 0.12.1 or later
Is CVE-2013-7222 being exploited?
Low — EPSS is 2.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.12.1