Ruby on Rails HTTP Digest Authentication Security Bypass Vulnerability


Description   A vulnerability has been identified in Ruby on Rails, which could be exploited by attackers to bypass security restrictions. This issue is caused by an error when handling the block passed to "authenticate_or_request_with_http_digest()", which could allow attackers to bypass authentication by providing an invalid username with an empty password.
     
Vulnerable Products   Vulnerable Software:
Ruby on Rails version 2.3.2 and prior
     
Solution   Apply patches : http://github.com/rails/rails/commit/056ddbdcfb07f0b5c7e6ed8a35f6c3b55b4ab489
     
CVE   CVE-2009-2422
     
References   http://weblog.rubyonrails.org/2009/6/3/security-problem-with-authenticate_with_http_digest
http://n8.tumblr.com/post/117477059/security-hole-found-in-rails-2-3s
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
Possible buffer overflow in HTTP request/reply
3.2.0
     


 
 
 
 
 Risk level 
Moderate 

 Vulnerability First Public Report Date 
2009-07-07 

 Target Type 
Server 

 Possible exploit 
Local & Remote