CVE-2015-7576
published 2016-02-16CVE-2015-7576: The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action…
PriorityP429low3.7CVSS 3.0
AVNACHPRNUINSUCLINAN
EPSS
4.88%
91.1th percentile
The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actionpack_project | actionpack | >= 3.1.0 < 3.2.22.1 | 3.2.22.1 |
| actionpack_project | actionpack | >= 4.0.0 < 4.1.14.1 | 4.1.14.1 |
| debian | rails | < rails 2:4.2.5.1-1 (bookworm) | rails 2:4.2.5.1-1 (bookworm) |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv3.03.7LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv3.7LOW
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller
vendor_redhat·2016-01-25·CVSS 3.7
CVE-2015-7576 [LOW] CWE-385 rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller
rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller
The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.
A flaw was found in the way the Action Controller component compared user names and passwords when performing HTTP basic authentication. Time taken to compare strings could differ depending on input, possibly allowing a remote attacker to determine va
Debian
CVE-2015-7576: rails - The http_basic_authenticate_with method in actionpack/lib/action_controller/meta...
vendor_debian·2015·CVSS 3.7
CVE-2015-7576 [LOW] CVE-2015-7576: rails - The http_basic_authenticate_with method in actionpack/lib/action_controller/meta...
The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.
Scope: local
bookworm: resolved (fixed in 2:4.2.5.1-1)
bullseye: resolved (fixed in 2:4.2.5.1-1)
forky: resolved (fixed in 2:4.2.5.1-1)
sid: resolved (fixed in 2:4.2.5.1-1)
trixie: resolved (fixed in 2:4.2.5.1-1)
OSV
actionpack is vulnerable to remote bypass authentication
osv·2017-10-24
CVE-2015-7576 [LOW] actionpack is vulnerable to remote bypass authentication
actionpack is vulnerable to remote bypass authentication
The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.
GHSA
actionpack is vulnerable to remote bypass authentication
ghsa·2017-10-24
CVE-2015-7576 [LOW] actionpack is vulnerable to remote bypass authentication
actionpack is vulnerable to remote bypass authentication
The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.
OSV
CVE-2015-7576: The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication
osv·2016-02-16·CVSS 3.7
CVE-2015-7576 [LOW] CVE-2015-7576: The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication
The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.
No detection rules found.
No public exploits indexed.
HackerOne
http_basic_authenticate_with is suseptible to timing attacks.
hackerone·2016-03-13·CVSS 3.7
CVE-2015-7576 [LOW] http_basic_authenticate_with is suseptible to timing attacks.
http_basic_authenticate_with is suseptible to timing attacks.
Timing attack vulnerability in basic authentication in Action Controller.
There is a timing attack vulnerability in the basic authentication support
in Action Controller. This vulnerability has been assigned the CVE
identifier CVE-2015-7576.
Versions Affected: All.
Not affected: None.
Fixed Versions: 5.0.0.beta1.1, 4.2.5.1, 4.1.14.1, 3.2.22.1
Impact
Due to the way that Action Controller compares user names and passwords in
basic authentication authorization code, it is possible for an attacker to
analyze the time taken by a response and intuit the password.
For example, this string comparison:
"foo" == "bar"
is possibly faster than this comparison:
"foo" == "fo1"
Attackers can use this information to attempt to guess th
Bugzilla
CVE-2015-7576 rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller
bugzilla·2016-01-26·CVSS 3.7
CVE-2015-7576 [LOW] CVE-2015-7576 rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller
CVE-2015-7576 rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller
It was found that due to the way that Action Controller compares user names and passwords in basic authentication authorization code, it is possible for an attacker to analyze the time taken by a response and intuit the password.
External References:
https://groups.google.com/forum/#!msg/rubyonrails-security/ANv0HDHEC3k/mt7wNGxbFQAJ
http://weblog.rubyonrails.org/2016/1/25/Rails-5-0-0-beta1-1-4-2-5-1-4-1-14-1-3-2-22-1-and-rails-html-sanitizer-1-0-3-have-been-released/
Discussion:
Created rubygem-activesupport tracking bugs for this issue:
Affects: fedora-all [bug 1301999]
---
Created rubygem-actionpack tracking bugs for this issue:
Affects: fedora-all [bug 1301996]
---
Upstr
Bugzilla
CVE-2015-7576 rubygem-activesupport: rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller [fedora-all]
bugzilla·2016-01-26·CVSS 3.7
CVE-2015-7576 [LOW] CVE-2015-7576 rubygem-activesupport: rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller [fedora-all]
CVE-2015-7576 rubygem-activesupport: rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit m
Bugzilla
CVE-2015-7576 rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller [fedora-all]
bugzilla·2016-01-26·CVSS 3.7
CVE-2015-7576 [LOW] CVE-2015-7576 rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller [fedora-all]
CVE-2015-7576 rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Bugzilla
CVE-2015-7576 rubygem-rails: Timing attack vulnerability in basic authentication in Action Controller [fedora-all]
bugzilla·2016-01-26·CVSS 3.7
CVE-2015-7576 [LOW] CVE-2015-7576 rubygem-rails: Timing attack vulnerability in basic authentication in Action Controller [fedora-all]
CVE-2015-7576 rubygem-rails: Timing attack vulnerability in basic authentication in Action Controller [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue af
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178043.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178047.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178067.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178068.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00053.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00034.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00043.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0296.htmlhttp://www.debian.org/security/2016/dsa-3464http://www.openwall.com/lists/oss-security/2016/01/25/8http://www.securityfocus.com/bid/81803http://www.securitytracker.com/id/1034816https://groups.google.com/forum/message/raw?msg=ruby-security-ann/ANv0HDHEC3k/T8Hgq-hYEgAJhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178043.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178047.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178067.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178068.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00053.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00034.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00043.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0296.htmlhttp://www.debian.org/security/2016/dsa-3464http://www.openwall.com/lists/oss-security/2016/01/25/8http://www.securityfocus.com/bid/81803http://www.securitytracker.com/id/1034816https://groups.google.com/forum/message/raw?msg=ruby-security-ann/ANv0HDHEC3k/T8Hgq-hYEgAJ
2016-02-16
Published