Authlogic Information Exposure vulnerability
Moderate severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Jan 26, 2023
Description
Published by the National Vulnerability Database
Jan 4, 2013
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Jan 26, 2023
Last updated
Jan 26, 2023
The Authlogic gem for Ruby on Rails prior to version 3.3.0 makes potentially unsafe
find_by_id
method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known secret_token value, as demonstrated by a value contained insecret_token.rb
in an open-source product.References