Ruby on Rails < 1.2.6 Cookie Related Session Fixation
Medium Nessus Network Monitor Plugin ID 4299
SynopsisThe remote server can be used to attack user authentication data.
DescriptionThe remote server is running the Ruby on Rails web application.
This version of Rails is reported to be vulnerable to a flaw in the way that it handles authentication data. Allegedly, the 'lib/action_controller/cgi_process.rb' script is vulnerable to a flaw that would allow an attacker to steal cookie data. An attacker could then use this data to gain access to the application with the user's credentials.
SolutionUpgrade to version 1.2.6 or higher.