CVE-2012-3424

medium
Published 2012-07-26 · Modified 2025-01-22
CVSS v3
CVSS v2
5.0
VIR risk
5.0

Description

The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attackers to cause a denial of service by leveraging access to an application that uses a with_http_digest helper method, as demonstrated by the authenticate_or_request_with_http_digest method.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-3424

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsactionpack!>= 2.3.5, <= 2.3.14||<~> 3.0.16~> 3.0.16
ruby RubyGemsactionpack>=3.0.0.beta,<3.0.163.0.16
ruby RubyGemsactionpack>=3.1.0,<3.1.73.1.7
ruby RubyGemsactionpack>=3.2.0,<3.2.73.2.7
ruby RubyGemsactionpack<2.3.52.3.5

Application impact

VendorProductVersionsFixed
rubyonrailsrails3.0.0
rubyonrailsrails3.0.1
rubyonrailsrails3.0.2
rubyonrailsrails3.0.3
rubyonrailsrails3.0.4
rubyonrailsrails3.0.5
rubyonrailsrails3.0.6
rubyonrailsrails3.0.7
rubyonrailsrails3.0.8
rubyonrailsrails3.0.9
rubyonrailsrails3.0.10
rubyonrailsrails3.0.11
rubyonrailsrails3.0.12
rubyonrailsrails3.0.13
rubyonrailsrails3.0.14
rubyonrailsruby_on_rails3.0.4
rubyonrailsrails3.1.0
rubyonrailsrails3.1.1
rubyonrailsrails3.1.2
rubyonrailsrails3.1.3
rubyonrailsrails3.1.4
rubyonrailsrails3.1.5
rubyonrailsrails3.1.6
rubyonrailsrails3.2.0
rubyonrailsrails3.2.1
rubyonrailsrails3.2.2
rubyonrailsrails3.2.3
rubyonrailsrails3.2.4
rubyonrailsrails3.2.5
rubyonrailsrails3.2.6

References

CWEs

CWE-287

Verify integrity in audit chain (admin only). AS-IS.