MEDIUM
GHSA-g897-cgfc-7q8v
Fat Free CRM has fixed token value
Quick fix
GHSA-g897-cgfc-7q8v — fat_free_crm: upgrade to the fixed version with the command below.
bundle update fat_free_crmDetails
`config/initializers/secret_token.rb` in Fat Free CRM before 0.12.1 has a fixed `FatFreeCRM::Application.config.secret_token` value, which makes it easier for remote attackers to spoof signed cookies by referring to the key in the source code.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2013-7222[ADVISORY]
- https://github.com/fatfreecrm/fat_free_crm/issues/300[WEB]
- https://github.com/fatfreecrm/fat_free_crm/commit/93c182dd4c6f3620b721d2a15ba6a6ecab5669df[WEB]
- https://github.com/fatfreecrm/fat_free_crm[PACKAGE]
- https://github.com/fatfreecrm/fat_free_crm/wiki/Fixing-security-vulnerabilities-%2827th-Dec-2013%29[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/fat_free_crm/CVE-2013-7222.yml[WEB]
- http://openwall.com/lists/oss-security/2013/12/28/2[WEB]
- http://seclists.org/fulldisclosure/2013/Dec/199[WEB]