GHSA-64qm-hrgp-pgr9
Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect
Quick fix
GHSA-64qm-hrgp-pgr9 — mechanize: upgrade to the fixed version with the command below.
bundle update mechanizeDetails
**Summary**
Mechanize (rubygem) `< v2.8.5` leaks the `Authorization` header after a redirect to a different port on the same site.
**Mitigation**
Upgrade to Mechanize v2.8.5 or later.
**Notes**
See [https://curl.se/docs/CVE-2022-27776.html](CVE-2022-27776) for a similar vulnerability in curl.
Cookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:
> Cookies do not provide isolation by port. If a cookie is readable > by a service running on one port, the cookie is also readable by a > service running on another port of the same server. If a cookie is > writable by a service on one port, the cookie is also writable by a > service running on another port of the same server. For this > reason, servers SHOULD NOT both run mutually distrusting services on > different ports of the same host and use cookies to store security- > sensitive information.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/sparklemotion/mechanize/security/advisories/GHSA-64qm-hrgp-pgr9[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-31033[ADVISORY]
- https://github.com/sparklemotion/mechanize/commit/c7fe6996a5b95f9880653ba3bc548a8d4ef72317[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/mechanize/CVE-2022-31033.yml[WEB]
- https://github.com/sparklemotion/mechanize[PACKAGE]