Vulnerabilities > CVE-2013-7134 - Credentials Management vulnerability in Phusion Juvia

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
phusion
CWE-255

Summary

Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by leveraging the secret key in app/config/initializers/secret_token.rb, related to cookies.

Vulnerable Configurations

Part Description Count
Application
Phusion
1

Common Weakness Enumeration (CWE)