CVE-2015-1820 REJECTED

REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.

EPSS 3.72% · 87.9th percentile

Risk Scores

EPSS Score
3.72%
87.9th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSruby-rest-client0, 1.6.7-6

Timeline

References

Open in Interactive Console →