Ruby on Rails HTTP Digest Authentication Security Bypass Vulnerability
Description
A vulnerability has been identified in Ruby on Rails, which could be exploited by attackers to bypass security restrictions. This issue is caused by an error when handling the block passed to "authenticate_or_request_with_http_digest()", which could allow attackers to bypass authentication by providing an invalid username with an empty password.
Vulnerable Products
Vulnerable Software: Ruby on Rails version 2.3.2 and prior