REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.
{
"severity": "CRITICAL",
"github_reviewed": true,
"cwe_ids": [
"CWE-384"
],
"nvd_published_at": null,
"github_reviewed_at": "2020-06-16T20:54:58Z"
}