CVE-2009-3086
published 2009-09-08CVE-2009-3086: A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature…
PriorityP421medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.23%
80.8th percentile
A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to forge a digest via multiple attempts.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actionpack_project | actionpack | >= 2.1.0 < 2.2.3 | 2.2.3 |
| actionpack_project | actionpack | >= 2.3.0 < 2.3.4 | 2.3.4 |
| debian | rails | < rails 2.2.3-1 (bookworm) | rails 2.2.3-1 (bookworm) |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | >= 0 < 2.2.3-1 | 2.2.3-1 |
| rubyonrails | rails | >= 0 < 2.2.3-1 | 2.2.3-1 |
| rubyonrails | rails | >= 0 < 2.2.3-1 | 2.2.3-1 |
| rubyonrails | rails | >= 0 < 2.2.3-1 | 2.2.3-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
actionpack and activesupport vulnerable to information leaks
osv·2017-10-24
CVE-2009-3086 [MEDIUM] actionpack and activesupport vulnerable to information leaks
actionpack and activesupport vulnerable to information leaks
A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to forge a digest via multiple attempts.
GHSA
actionpack and activesupport vulnerable to information leaks
ghsa·2017-10-24
CVE-2009-3086 [MEDIUM] CWE-200 actionpack and activesupport vulnerable to information leaks
actionpack and activesupport vulnerable to information leaks
A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to forge a digest via multiple attempts.
OSV
CVE-2009-3086: A certain algorithm in Ruby on Rails 2
osv·2009-09-08·CVSS 5.0
CVE-2009-3086 [MEDIUM] CVE-2009-3086: A certain algorithm in Ruby on Rails 2
A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to forge a digest via multiple attempts.
Debian
CVE-2009-3086: rails - A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4...
vendor_debian·2009·CVSS 5.0
CVE-2009-3086 [MEDIUM] CVE-2009-3086: rails - A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4...
A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to forge a digest via multiple attempts.
Scope: local
bookworm: resolved (fixed in 2.2.3-1)
bullseye: resolved (fixed in 2.2.3-1)
forky: resolved (fixed in 2.2.3-1)
sid: resolved (fixed in 2.2.3-1)
trixie: resolved (fixed in 2.2.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-3086 rubygem-actionpack: Message digest forgery [epel-5]
bugzilla·2013-05-08·CVSS 5.0
CVE-2009-3086 [MEDIUM] CVE-2009-3086 rubygem-actionpack: Message digest forgery [epel-5]
CVE-2009-3086 rubygem-actionpack: Message digest forgery [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for rubygem-ac
Bugzilla
CVE-2009-3086 rubygem-actionpack: Message digest forgery
bugzilla·2009-09-09·CVSS 5.0
CVE-2009-3086 [MEDIUM] CVE-2009-3086 rubygem-actionpack: Message digest forgery
CVE-2009-3086 rubygem-actionpack: Message digest forgery
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3086 to
the following vulnerability:
A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x
before 2.3.4, leaks information about the complexity of message-digest
signature verification in the cookie store, which might allow remote
attackers to forge a digest via multiple attempts.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3086
http://weblog.rubyonrails.org/2009/9/4/timing-weakness-in-ruby-on-rails
http://www.vupen.com/english/advisories/2009/2544
Upstream patches:
http://weblog.rubyonrails.org/assets/2009/9/4/2-2-timing-weakness.patch
http://weblog.rubyonrails.org/assets/2009/9/4/2-3-timing-weakness.patch
Discussion:
This
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.htmlhttp://secunia.com/advisories/36600http://weblog.rubyonrails.org/2009/9/4/timing-weakness-in-ruby-on-railshttp://www.debian.org/security/2011/dsa-2260http://www.securityfocus.com/bid/37427http://www.vupen.com/english/advisories/2009/2544http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.htmlhttp://secunia.com/advisories/36600http://weblog.rubyonrails.org/2009/9/4/timing-weakness-in-ruby-on-railshttp://www.debian.org/security/2011/dsa-2260http://www.securityfocus.com/bid/37427http://www.vupen.com/english/advisories/2009/2544
2009-09-08
Published