Quantcast
Channel: Security Bulletins
Viewing all articles
Browse latest Browse all 25

Cloud Help Desk Ruby on Rails Update

$
0
0

Publish Date: Mar. 29, 2019

Summary

We've updated the Ruby on Rails version used by the Spiceworks Cloud Help Desk in order to patch a security vulnerability.

Who’s Affected?

At this time, we do not believe anyone was impacted by the vulnerability patched in this update.

Details

Ruby on Rails was discovered to contain a vulnerability that could allow an attacker to obtain the development mode secret token. This could eventually allow for a remote code execution exploit.

Mitigating Factors

The vulnerability would have to be purposefully exploited.

Security Update Information

The Spiceworks Cloud Help Desk was updated in March 2019 to run a patched version of Ruby on Rails.

Acknowledgements

none

References and Further Reading

Click here for more information on the Ruby on Rails vulnerability.

Revisions

v1.0: (Mar. 29, 2019): Bulletin...


Viewing all articles
Browse latest Browse all 25

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>