Vulnerability Description
An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the Passport.js contents of the session cookie to contain the ID number of the account they wish to take over, and re-sign it using the hard coded secret.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gamerpolls | Gamerpolls | 0.4.6 |
Related Weaknesses (CWE)
References
- https://github.com/GamerPolls/gamerpolls.com/blob/03ccbaf219410e0a45390d0efc1201PatchThird Party Advisory
- https://github.com/GamerPolls/gamerpolls.com/pull/56PatchThird Party Advisory
- https://www.digitalinterruption.com/single-post/2018/06/04/Are-Your-Cookies-TellExploitThird Party Advisory
- https://github.com/GamerPolls/gamerpolls.com/blob/03ccbaf219410e0a45390d0efc1201PatchThird Party Advisory
- https://github.com/GamerPolls/gamerpolls.com/pull/56PatchThird Party Advisory
- https://www.digitalinterruption.com/single-post/2018/06/04/Are-Your-Cookies-TellExploitThird Party Advisory
FAQ
What is CVE-2018-10966?
CVE-2018-10966 is a vulnerability with a CVSS score of 7.3 (HIGH). An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the Passport.js contents of the session cookie to contai...
How severe is CVE-2018-10966?
CVE-2018-10966 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10966?
Check the references section above for vendor advisories and patch information. Affected products include: Gamerpolls Gamerpolls.