CVE-2009-2422
published 2009-07-10CVE-2009-2422: The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an…
PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.38%
87.4th percentile
The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending an invalid username without a password.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.6.0 < 10.6.3 | 10.6.3 |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | >= 10.6.0 < 10.6.3 | 10.6.3 |
| debian | rails | < rails 2.3.5-1 (bookworm) | rails 2.3.5-1 (bookworm) |
| rubyonrails | rails | >= 0 < 2.3.5-1 | 2.3.5-1 |
| rubyonrails | rails | >= 0 < 2.3.5-1 | 2.3.5-1 |
| rubyonrails | rails | >= 0 < 2.3.5-1 | 2.3.5-1 |
| rubyonrails | rails | >= 0 < 2.3.5-1 | 2.3.5-1 |
| rubyonrails | rails | >= 0 < 2.3.3 | 2.3.3 |
| rubyonrails | ruby_on_rails | < 2.3.3 | 2.3.3 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
rails vulnerable to improper authentication
osv·2017-10-24
CVE-2009-2422 [CRITICAL] rails vulnerable to improper authentication
rails vulnerable to improper authentication
The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending an invalid username without a password.
GHSA
rails vulnerable to improper authentication
ghsa·2017-10-24
CVE-2009-2422 [CRITICAL] CWE-287 rails vulnerable to improper authentication
rails vulnerable to improper authentication
The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending an invalid username without a password.
OSV
CVE-2009-2422: The example code for the digest authentication functionality (http_authentication
osv·2009-07-10·CVSS 9.8
CVE-2009-2422 [CRITICAL] CVE-2009-2422: The example code for the digest authentication functionality (http_authentication
The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending an invalid username without a password.
Debian
CVE-2009-2422: rails - The example code for the digest authentication functionality (http_authenticatio...
vendor_debian·2009·CVSS 9.8
CVE-2009-2422 [CRITICAL] CVE-2009-2422: rails - The example code for the digest authentication functionality (http_authenticatio...
The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending an invalid username without a password.
Scope: local
bookworm: resolved (fixed in 2.3.5-1)
bullseye: resolved (fixed in 2.3.5-1)
forky: resolved (fixed in 2.3.5-1)
sid: resolved (fixed in 2.3.5-1)
trixie: resolved (fixed in 2.3.5-1)
Red Hat
rubygem-actionpack: authenticate_with_http_digest authentication bypass
vendor_redhat·CVSS 9.8
CVE-2009-2422 [CRITICAL] rubygem-actionpack: authenticate_with_http_digest authentication bypass
rubygem-actionpack: authenticate_with_http_digest authentication bypass
The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending an invalid username without a password.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlhttp://n8.tumblr.com/post/117477059/security-hole-found-in-rails-2-3shttp://secunia.com/advisories/35702http://support.apple.com/kb/HT4077http://weblog.rubyonrails.org/2009/6/3/security-problem-with-authenticate_with_http_digesthttp://www.securityfocus.com/bid/35579http://www.vupen.com/english/advisories/2009/1802https://exchange.xforce.ibmcloud.com/vulnerabilities/51528http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlhttp://n8.tumblr.com/post/117477059/security-hole-found-in-rails-2-3shttp://secunia.com/advisories/35702http://support.apple.com/kb/HT4077http://weblog.rubyonrails.org/2009/6/3/security-problem-with-authenticate_with_http_digesthttp://www.securityfocus.com/bid/35579http://www.vupen.com/english/advisories/2009/1802https://exchange.xforce.ibmcloud.com/vulnerabilities/51528
2009-07-10
Published