Vulnerability in Rails 2.3 HTTP Authentication
There has been a security vulnerability in Rails in the HTTP digest authentication in Rails 2.3. That way someone can authenticate without any user name and password. The HTTP basic authentication seems to be not vulnerable to this problem.
The problem arises in the authenticate_or_request_with_http_digest method which will proceed even if the user name check returns nil.
You can find out more, including countermeasures at Nate's blog and the Rails weblog.


Recent comments
1 year 23 weeks ago
1 year 23 weeks ago
1 year 25 weeks ago
1 year 27 weeks ago
1 year 42 weeks ago
1 year 45 weeks ago
1 year 45 weeks ago
1 year 45 weeks ago
1 year 46 weeks ago
1 year 48 weeks ago