Description
The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attackers to cause a denial of service by leveraging access to an application that uses a with_http_digest helper method, as demonstrated by the authenticate_or_request_with_http_digest method.
Remediation
References
Related Vulnerabilities
MySQL CVE-2017-3455 Vulnerability (CVE-2017-3455)
WordPress Plugin WooCommerce Cross-Site Scripting (3.5.0)
Angular Server-Side Request Forgery (SSRF) Vulnerability (CVE-2026-41423)
WordPress 4.1.x Possible SQL Injection Vulnerability (4.1 - 4.1.19)
WordPress Plugin Baggage Freight Shipping Australia Arbitrary File Upload (0.1.0)