MGASA-2015-0227

Advisory lineage Upstream: 2 Downstream: 0
Published: 15 May 2015, 18:23
Last modified:16 Apr 2026, 06:23

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

15 May 2015, 18:23
Published
Vulnerability first disclosed
16 Apr 2026, 06:23
Last Modified
Vulnerability information updated

Description

Updated ruby-rest-client packages fix security vulnerabilities Updated ruby-rest-client packages fix security vulnerability: When Ruby rest-client processes an HTTP redirection response, it blindly passes along the values from any Set-Cookie headers to the redirection target, regardless of domain, path, or expiration. This can be used in a session fixation attack or in stealing cookies (CVE-2015-1820). REST Client for Ruby contains a flaw that is due to the application logging password information in plaintext. This may allow a local attacker to gain access to password information (CVE-2015-3448). The ruby-rest-client package has been updated to version 1.8.0, fixing these issues and several other bugs. Refer to the upstream changelog for more details.

Affected Systems

  • mageiaruby-http-cookie

    < 1.0.2-1.mga4

  • mageiaruby-netrc

    < 0.10.3-1.mga4

  • mageiaruby-rest-client

    < 1.8.0-2.mga4

References (5)