VDB
Sign up
MEDIUM6.2

GHSA-844m-cpr9-jcmh

Rails Multisite secure/signed cookies share secrets between sites in a multi-site application

Quick fix

GHSA-844m-cpr9-jcmh — rails_multisite: upgrade to the fixed version with the command below.

bundle update rails_multisite

Details

### Impact This vulnerability impacts any Rails applications using `rails_multisite` alongside Rails' signed/encrypted cookies. Depending on how the application makes use of these cookies, it may be possible for an attacker to re-use cookies on different 'sites' within a multi-site Rails application.

### Patches The issue has been patched in v4 of the `rails_multisite` gem. Note that this upgrade will invalidate all previous signed/encrypted cookies. The impact of this invalidation will vary based on the application architecture.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rails_multisite
Introduced in: 0Fixed in: 4.0.0
Fixbundle update rails_multisite

References