Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.2 RubyGems

Rails Multisite secure/signed cookies share secrets between sites in a multi-site application

GHSA-844m-cpr9-jcmh · CVE-2021-41263

Published · Modified

Description

Impact

This vulnerability impacts any Rails applications using rails_multisite alongside Rails' signed/encrypted cookies. Depending on how the application makes use of these cookies, it may be possible for an attacker to re-use cookies on different 'sites' within a multi-site Rails application.

Patches

The issue has been patched in v4 of the rails_multisite gem. Note that this upgrade will invalidate all previous signed/encrypted cookies. The impact of this invalidation will vary based on the application architecture.

Ready to move

Start Securing

Free, no credit card | First findings in minutes