config/initializers/secret_token.rb in Fat Free CRM before 0.12.1 has a fixed FatFreeCRM::Application.config.secret_token value, which makes it easier for remote attackers to spoof signed cookies by referring to the key in the source code.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fat_free_crm | Fatfreecrm | * | 0.12.0 (including) |
Fat_free_crm | Fatfreecrm | 0.9.6 (including) | 0.9.6 (including) |
Fat_free_crm | Fatfreecrm | 0.9.7 (including) | 0.9.7 (including) |
Fat_free_crm | Fatfreecrm | 0.9.8 (including) | 0.9.8 (including) |
Fat_free_crm | Fatfreecrm | 0.9.9 (including) | 0.9.9 (including) |
Fat_free_crm | Fatfreecrm | 0.9.10 (including) | 0.9.10 (including) |
Fat_free_crm | Fatfreecrm | 0.10.1 (including) | 0.10.1 (including) |
Fat_free_crm | Fatfreecrm | 0.11.0 (including) | 0.11.0 (including) |
Fat_free_crm | Fatfreecrm | 0.11.1 (including) | 0.11.1 (including) |
Fat_free_crm | Fatfreecrm | 0.11.2 (including) | 0.11.2 (including) |