GHSA-844m-cpr9-jcmh

    Dashboard / Vulnerabilities / GHSA-844m-cpr9-jcmh

    GHSA-844m-cpr9-jcmh

    Published: 15 Nov 2021Last Modified: 8 Jul 2026

    Summary: Rails Multisite secure/signed cookies share secrets between sites in a multi-site application

    Details: ### Impact This vulnerability impacts any Rails applications using `rails_multisite` alongside Rails' signed/encrypted cookies. Depending on how the application makes use of these cookies, it may be possible for an attacker to re-use cookies on different 'sites' within a multi-site Rails application. ### Patches The issue has been patched in v4 of the `rails_multisite` gem. Note that this upgrade will invalidate all previous signed/encrypted cookies. The impact of this invalidation will vary based on the application architecture.

    Affected packages

    Package

    Name: rails_multisite

    Purl: pkg:gem/rails_multisite

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.0.0

    Affected versions

    0.0.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-844m-cpr9-jcmh | CVE-DB