cbcvebase.
CVE-2009-2422
published 2009-07-10

CVE-2009-2422: The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an…

PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.38%
87.4th percentile
The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending an invalid username without a password.

Affected

11 ranges
VendorProductVersion rangeFixed in
applemac_os_x
applemac_os_x>= 10.6.0 < 10.6.310.6.3
applemac_os_x_server
applemac_os_x_server>= 10.6.0 < 10.6.310.6.3
debianrails< rails 2.3.5-1 (bookworm)rails 2.3.5-1 (bookworm)
rubyonrailsrails>= 0 < 2.3.5-12.3.5-1
rubyonrailsrails>= 0 < 2.3.5-12.3.5-1
rubyonrailsrails>= 0 < 2.3.5-12.3.5-1
rubyonrailsrails>= 0 < 2.3.5-12.3.5-1
rubyonrailsrails>= 0 < 2.3.32.3.3
rubyonrailsruby_on_rails< 2.3.32.3.3

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.