GHSA-64qm-hrgp-pgr9

    Dashboard / Vulnerabilities / GHSA-64qm-hrgp-pgr9

    GHSA-64qm-hrgp-pgr9

    Published: 9 Jun 2022Last Modified: 8 Nov 2023

    Summary: Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect

    Details: **Summary** Mechanize (rubygem) `< v2.8.5` leaks the `Authorization` header after a redirect to a different port on the same site. **Mitigation** Upgrade to Mechanize v2.8.5 or later. **Notes** See [https://curl.se/docs/CVE-2022-27776.html](CVE-2022-27776) for a similar vulnerability in curl. Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part: > Cookies do not provide isolation by port. If a cookie is readable > by a service running on one port, the cookie is also readable by a > service running on another port of the same server. If a cookie is > writable by a service on one port, the cookie is also writable by a > service running on another port of the same server. For this > reason, servers SHOULD NOT both run mutually distrusting services on > different ports of the same host and use cookies to store security- > sensitive information.

    Affected packages

    Package

    Name: mechanize

    Purl: pkg:gem/mechanize

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.8.5

    Affected versions

    0.1.0
    0.1.1
    0.1.2
    0.1.3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-64qm-hrgp-pgr9 | CVE-DB