Critical severity9.8NVD Advisory· Published Jul 10, 2009· Updated Apr 23, 2026
CVE-2009-2422
CVE-2009-2422
Description
The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending an invalid username without a password.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
railsRubyGems | < 2.3.3 | 2.3.3 |
Affected products
5cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*range: >=10.6.0,<10.6.3
- cpe:2.3:o:apple:mac_os_x:10.5.8:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:*range: >=10.6.0,<10.6.3
- cpe:2.3:o:apple:mac_os_x_server:10.5.8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
13- weblog.rubyonrails.org/2009/6/3/security-problem-with-authenticate_with_http_digestnvdPatchWEB
- www.securityfocus.com/bid/35579nvdBroken LinkPatchThird Party AdvisoryVDB Entry
- www.vupen.com/english/advisories/2009/1802nvdBroken LinkPatchVendor Advisory
- n8.tumblr.com/post/117477059/security-hole-found-in-rails-2-3snvdExploitPatchWEB
- secunia.com/advisories/35702nvdBroken LinkVendor Advisory
- support.apple.com/kb/HT4077nvdThird Party AdvisoryWEB
- exchange.xforce.ibmcloud.com/vulnerabilities/51528nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-rxq3-gm4p-5fj4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2009-2422ghsaADVISORY
- lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlnvdMailing ListWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/rails/CVE-2009-2422.ymlghsaWEB
- web.archive.org/web/20090711160153/http://secunia.com/advisories/35702ghsaWEB
- web.archive.org/web/20200229192617/http://www.securityfocus.com/bid/35579ghsaWEB
News mentions
0No linked articles in our index yet.