GHSA-64qm-hrgp-pgr9
Dashboard / Vulnerabilities / GHSA-64qm-hrgp-pgr9
Summary: Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
Details: **Summary** Mechanize (rubygem) `< v2.8.5` leaks the `Authorization` header after a redirect to a different port on the same site. **Mitigation** Upgrade to Mechanize v2.8.5 or later. **Notes** See [https://curl.se/docs/CVE-2022-27776.html](CVE-2022-27776) for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part: > Cookies do not provide isolation by port. If a cookie is readable > by a service running on one port, the cookie is also readable by a > service running on another port of the same server. If a cookie is > writable by a service on one port, the cookie is also writable by a > service running on another port of the same server. For this > reason, servers SHOULD NOT both run mutually distrusting services on > different ports of the same host and use cookies to store security- > sensitive information.
References: https://github.com/sparklemotion/mechanize/security/advisories/GHSA-64qm-hrgp-pgr9, https://nvd.nist.gov/vuln/detail/CVE-2022-31033, https://github.com/sparklemotion/mechanize/commit/c7fe6996a5b95f9880653ba3bc548a8d4ef72317, https://github.com/rubysec/ruby-advisory-db/blob/master/gems/mechanize/CVE-2022-31033.yml, https://github.com/sparklemotion/mechanize
Affected packages
Package
Name: mechanize
Purl: pkg:gem/mechanize
Affected ranges
Type: ECOSYSTEM
Events:
