CVE-2013-7134 Information

Description

Juvia uses the same secret key for all installations which allows remote attackers to have unspecified impact by leveraging the secret key in app/config/initializers/secret_token.rb related to cookies.

Reference

http://www.openwall.com/lists/oss-security/2013/12/16/3 http://www.openwall.com/lists/oss-security/2013/12/18/1 https://github.com/phusion/juvia/issues/55

Share on: