GHSA-44vf-8ffm-v2qh

Suggest an improvement
Source
https://github.com/advisories/GHSA-44vf-8ffm-v2qh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-44vf-8ffm-v2qh/GHSA-44vf-8ffm-v2qh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-44vf-8ffm-v2qh
Published
2020-09-02T15:42:47Z
Modified
2020-08-31T18:34:35Z
Summary
Sensitive Data Exposure in rails-session-decoder
Details

All versions of rails-session-decoder are missing verification of the Message Authentication Code appended to the cookies. This may lead to decryption of cipher text thus exposing encrypted information.

Recommendation

No fix is currently available. Consider using an alternative module until a fix is made available.

Database specific
{
    "cwe_ids": [],
    "github_reviewed_at": "2020-08-31T18:34:35Z",
    "github_reviewed": true,
    "severity": "HIGH",
    "nvd_published_at": null
}
References

Affected packages

npm / rails-session-decoder

Package

Name
rails-session-decoder
View open source insights on deps.dev
Purl
pkg:npm/rails-session-decoder

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-44vf-8ffm-v2qh/GHSA-44vf-8ffm-v2qh.json"