CVE-2008-7311

EPSS 0.16%

Spree uses a hardcoded hash value

發布日:2022/5/17修改日:2024/12/7

描述

The session cookie store implementation in Spree 0.2.0 uses a hardcoded `config.action_controller_session` hash value (aka secret key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging an application that contains this value within the `config/environment.rb` file.

受影響套件(1)

參考連結(8)