CVE-2012-3424
published 2012-08-08CVE-2012-3424: The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and…
PriorityP424medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.91%
77.6th percentile
The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attackers to cause a denial of service by leveraging access to an application that uses a with_http_digest helper method, as demonstrated by the authenticate_or_request_with_http_digest method.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actionpack_project | actionpack | >= 0 < 2.3.5 | 2.3.5 |
| actionpack_project | actionpack | >= 3.0.0.beta < 3.0.16 | 3.0.16 |
| actionpack_project | actionpack | >= 3.1.0 < 3.1.7 | 3.1.7 |
| actionpack_project | actionpack | >= 3.2.0 < 3.2.7 | 3.2.7 |
| debian | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest
vendor_redhat·2012-07-26·CVSS 5.0
CVE-2012-3424 [MEDIUM] rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest
rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest
The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attackers to cause a denial of service by leveraging access to an application that uses a with_http_digest helper method, as demonstrated by the authenticate_or_request_with_http_digest method.
Debian
CVE-2012-3424: rails - The decode_credentials method in actionpack/lib/action_controller/metal/http_aut...
vendor_debian·2012·CVSS 5.0
CVE-2012-3424 [MEDIUM] CVE-2012-3424: rails - The decode_credentials method in actionpack/lib/action_controller/metal/http_aut...
The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attackers to cause a denial of service by leveraging access to an application that uses a with_http_digest helper method, as demonstrated by the authenticate_or_request_with_http_digest method.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
actionpack Improper Authentication vulnerability
osv·2017-10-24
CVE-2012-3424 [MEDIUM] actionpack Improper Authentication vulnerability
actionpack Improper Authentication vulnerability
The `decode_credentials` method in `actionpack/lib/action_controller/metal/http_authentication.rb` in Ruby on Rails before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attackers to cause a denial of service by leveraging access to an application that uses a `with_http_digest` helper method, as demonstrated by the `authenticate_or_request_with_http_digest` method.
GHSA
actionpack Improper Authentication vulnerability
ghsa·2017-10-24
CVE-2012-3424 [MEDIUM] CWE-287 actionpack Improper Authentication vulnerability
actionpack Improper Authentication vulnerability
The `decode_credentials` method in `actionpack/lib/action_controller/metal/http_authentication.rb` in Ruby on Rails before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attackers to cause a denial of service by leveraging access to an application that uses a `with_http_digest` helper method, as demonstrated by the `authenticate_or_request_with_http_digest` method.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3424 rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest [fedora-all]
bugzilla·2012-07-27·CVSS 5.0
CVE-2012-3424 [MEDIUM] CVE-2012-3424 rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest [fedora-all]
CVE-2012-3424 rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraprojec
Bugzilla
CVE-2012-3424 rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest
bugzilla·2012-07-27·CVSS 5.0
CVE-2012-3424 [MEDIUM] CVE-2012-3424 rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest
CVE-2012-3424 rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest
[email protected] reports:
DoS Vulnerability in authenticate_or_request_with_http_digest
There is a DoS vulnerability in Action Pack digest authentication handling in Rails.
This vulnerability has been assigned the CVE identifier CVE-2012-3424.
Versions Affected: 3.x.
Not affected: 2.3.5 - 2.3.14
Fixed Versions: 3.0.16, 3.1.7, 3.2.7
Impact
All users using Digest Authentication support in Rails should upgrade
immediately. Impacted code uses any of the `with_http_digest` controller
helper methods. For example:
class MyController < ApplicationController
def index
authenticate_or_request_with_http_digest(REALM) do |uname|
# ...
end
end
end
Releases
The 3.0.16, 3.1.7 & 3.2.7 releases a
Bugzilla
CVE-2012-3424 rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest [epel-5]
bugzilla·2012-07-27·CVSS 5.0
CVE-2012-3424 [MEDIUM] CVE-2012-3424 rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest [epel-5]
CVE-2012-3424 rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.or
http://lists.opensuse.org/opensuse-updates/2012-08/msg00046.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0154.htmlhttp://weblog.rubyonrails.org/2012/7/26/ann-rails-3-2-7-has-been-released/https://groups.google.com/group/rubyonrails-security/msg/244d32f2fa25147d?hl=en&dmode=source&output=gplainhttp://lists.opensuse.org/opensuse-updates/2012-08/msg00046.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0154.htmlhttp://weblog.rubyonrails.org/2012/7/26/ann-rails-3-2-7-has-been-released/https://groups.google.com/group/rubyonrails-security/msg/244d32f2fa25147d?hl=en&dmode=source&output=gplain
2012-08-08
Published