CVE-2021-41263

Exposure of Sensitive Information to an Unauthorized Actor in gem/rails_multisite

Identifiers

CVE-2021-41263, GHSA-844m-cpr9-jcmh

Package Slug

gem/rails_multisite

Vulnerability

Exposure of Sensitive Information to an Unauthorized Actor

Description

railsmultisite provides multi-db support for Rails applications.Depending on how the application makes use of these cookies, it may be possible for an attacker to re-use cookies on different 'sites' within a multi-site Rails application. The issue has been patched in v4 of the `railsmultisite` gem. Note that this upgrade will invalidate all previous signed/encrypted cookies. The impact of this invalidation will vary based on the application architecture.

Affected Versions

All versions before 4.0.0

Solution

Upgrade to version 4.0.0 or above.

Last Modified

2021-11-22

source