Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by leveraging the secret key in app/config/initializers/secret_token.rb, related to cookies.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
https://github.com/phusion/juvia/issues/55 | |
http://www.openwall.com/lists/oss-security/2013/12/16/3 | mailing list |
http://www.openwall.com/lists/oss-security/2013/12/18/1 | mailing list |