rest-client
A simple HTTP and REST client for Ruby, inspired by the Sinatra microframework style of specifying actions: get, put, post, delete.
Activity
- Latest release
- 7y ago
- Total releases
- 62
- Cadence
- ~13 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Mar 09, 2008
| Version | Released | |
|---|---|---|
2.1.0
minor
|
2.1.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
1.6.14
patch
3 CVEs
CVE-2019-15224
GHSA-333g-rpr4-7hxq
Aug 20, 2019
rest-client Gem Contains Malicious Code
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Users of an affected version should consider downgrading to the last non-affected version of 1.6.9, or upgrading to 1.7.x. Additionally, a set of other minor gems have been partially or completely yanked and are included in this advisory. These include cron_parser, coin_base, blockchain_wallet, awesome-bot, doge-coin, capistrano-colors, bitcoin_vanity, lita_coin, coming-soon, and omniauth_amazon. Affected versions
1.6.14
1.7.0.rc1
Fixed in
1.7.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2015-1820
GHSA-3fhf-6939-qg8p
Aug 13, 2018
rest-client Gem Vulnerable to Session Fixation
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. Affected versions
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
+ 6 more Show less
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
1.7.3
1.8.0.rc1
Fixed in
1.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
2.1.0.rc1
pre
|
2.1.0.rc1
pre
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.0.2
patch
|
2.0.2
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.1
patch
|
2.0.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.0
major
|
2.0.0
major
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.0.rc4
pre
|
2.0.0.rc4
pre
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.0.rc3
pre
|
2.0.0.rc3
pre
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.0.rc2
pre
|
2.0.0.rc2
pre
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
1.6.9
patch
2 CVEs
CVE-2015-1820
GHSA-3fhf-6939-qg8p
Aug 13, 2018
rest-client Gem Vulnerable to Session Fixation
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. Affected versions
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
+ 6 more Show less
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
1.7.3
1.8.0.rc1
Fixed in
1.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
2.0.0.rc1
pre
|
2.0.0.rc1
pre
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
1.8.0
minor
|
1.8.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.8.0.rc1
pre
1 CVE
CVE-2015-1820
GHSA-3fhf-6939-qg8p
Aug 13, 2018
rest-client Gem Vulnerable to Session Fixation
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. Affected versions
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
+ 6 more Show less
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
1.7.3
1.8.0.rc1
Fixed in
1.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.8.0.rc1
pre
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.7.3
patch
1 CVE
CVE-2015-1820
GHSA-3fhf-6939-qg8p
Aug 13, 2018
rest-client Gem Vulnerable to Session Fixation
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. Affected versions
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
+ 6 more Show less
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
1.7.3
1.8.0.rc1
Fixed in
1.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.7.3
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.7.2
patch
2 CVEs
CVE-2015-1820
GHSA-3fhf-6939-qg8p
Aug 13, 2018
rest-client Gem Vulnerable to Session Fixation
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. Affected versions
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
+ 6 more Show less
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
1.7.3
1.8.0.rc1
Fixed in
1.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev |
1.7.2
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.7.2.rc1
pre
2 CVEs
CVE-2015-1820
GHSA-3fhf-6939-qg8p
Aug 13, 2018
rest-client Gem Vulnerable to Session Fixation
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. Affected versions
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
+ 6 more Show less
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
1.7.3
1.8.0.rc1
Fixed in
1.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev |
1.7.2.rc1
pre
Dependencies (8)
Changelog
Compare changes
|
|
1.7.1
patch
2 CVEs
CVE-2015-1820
GHSA-3fhf-6939-qg8p
Aug 13, 2018
rest-client Gem Vulnerable to Session Fixation
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. Affected versions
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
+ 6 more Show less
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
1.7.3
1.8.0.rc1
Fixed in
1.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev |
1.7.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.7.0
minor
2 CVEs
CVE-2015-1820
GHSA-3fhf-6939-qg8p
Aug 13, 2018
rest-client Gem Vulnerable to Session Fixation
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. Affected versions
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
+ 6 more Show less
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
1.7.3
1.8.0.rc1
Fixed in
1.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.6.8
patch
2 CVEs
CVE-2015-1820
GHSA-3fhf-6939-qg8p
Aug 13, 2018
rest-client Gem Vulnerable to Session Fixation
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. Affected versions
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
+ 6 more Show less
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
1.7.3
1.8.0.rc1
Fixed in
1.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.6.8.rc1
pre
2 CVEs
CVE-2015-1820
GHSA-3fhf-6939-qg8p
Aug 13, 2018
rest-client Gem Vulnerable to Session Fixation
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. Affected versions
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
+ 6 more Show less
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
1.7.3
1.8.0.rc1
Fixed in
1.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.7.0.rc1
pre
3 CVEs
CVE-2019-15224
GHSA-333g-rpr4-7hxq
Aug 20, 2019
rest-client Gem Contains Malicious Code
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Users of an affected version should consider downgrading to the last non-affected version of 1.6.9, or upgrading to 1.7.x. Additionally, a set of other minor gems have been partially or completely yanked and are included in this advisory. These include cron_parser, coin_base, blockchain_wallet, awesome-bot, doge-coin, capistrano-colors, bitcoin_vanity, lita_coin, coming-soon, and omniauth_amazon. Affected versions
1.6.14
1.7.0.rc1
Fixed in
1.7.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2015-1820
GHSA-3fhf-6939-qg8p
Aug 13, 2018
rest-client Gem Vulnerable to Session Fixation
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. Affected versions
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
+ 6 more Show less
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
1.7.3
1.8.0.rc1
Fixed in
1.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.6.7
patch
2 CVEs
CVE-2015-1820
GHSA-3fhf-6939-qg8p
Aug 13, 2018
rest-client Gem Vulnerable to Session Fixation
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. Affected versions
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
+ 6 more Show less
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
1.7.3
1.8.0.rc1
Fixed in
1.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.6.5
patch
2 CVEs
CVE-2015-1820
GHSA-3fhf-6939-qg8p
Aug 13, 2018
rest-client Gem Vulnerable to Session Fixation
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. Affected versions
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
+ 6 more Show less
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
1.7.3
1.8.0.rc1
Fixed in
1.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.6.6
patch
2 CVEs
CVE-2015-1820
GHSA-3fhf-6939-qg8p
Aug 13, 2018
rest-client Gem Vulnerable to Session Fixation
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. Affected versions
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
+ 6 more Show less
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
1.7.3
1.8.0.rc1
Fixed in
1.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.6.3
patch
2 CVEs
CVE-2015-1820
GHSA-3fhf-6939-qg8p
Aug 13, 2018
rest-client Gem Vulnerable to Session Fixation
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. Affected versions
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
+ 6 more Show less
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
1.7.3
1.8.0.rc1
Fixed in
1.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.6.2.a
pre
2 CVEs
CVE-2015-1820
GHSA-3fhf-6939-qg8p
Aug 13, 2018
rest-client Gem Vulnerable to Session Fixation
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. Affected versions
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
+ 6 more Show less
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
1.7.3
1.8.0.rc1
Fixed in
1.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.6.1
patch
2 CVEs
CVE-2015-1820
GHSA-3fhf-6939-qg8p
Aug 13, 2018
rest-client Gem Vulnerable to Session Fixation
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. Affected versions
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
+ 6 more Show less
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
1.7.3
1.8.0.rc1
Fixed in
1.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.6.1.a
pre
2 CVEs
CVE-2015-1820
GHSA-3fhf-6939-qg8p
Aug 13, 2018
rest-client Gem Vulnerable to Session Fixation
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. Affected versions
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
+ 6 more Show less
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
1.7.3
1.8.0.rc1
Fixed in
1.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.6.0.a
pre
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.6.0
minor
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.5.0
minor
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.5.0.b
pre
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.4.2
patch
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.5.1
patch
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.5.0.a
pre
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.4.1
patch
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.4.0
minor
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.4.0.a
pre
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.3.0
minor
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.3.1
patch
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.2.0
minor
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.0.4
patch
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.0.3
patch
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.0.2
patch
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.0.1
patch
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
1.0
major
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
0.9.2
patch
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
0.9
minor
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev | ||
0.8.2
patch
1 CVE
CVE-2015-3448
GHSA-mx9f-w8qq-q5jf
Oct 24, 2017
rest-client allows local users to obtain sensitive information by reading the log
Low
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. Affected versions
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.7
0.8
0.8.1
+ 38 more Show less
0.8.2
0.9
0.9.2
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.0.a
1.4.1
1.4.2
1.5.0
1.5.0.a
1.5.0.b
1.5.1
1.6.0
1.6.0.a
1.6.1
1.6.1.a
1.6.14
1.6.2.a
1.6.3
1.6.5
1.6.6
1.6.7
1.6.8
1.6.8.rc1
1.6.9
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.2.rc1
Fixed in
1.7.3
References Updated Nov 30, 2024 · Source: OSV.dev |