{"id":"GHSA-64qm-hrgp-pgr9","summary":"Mechanize before v2.8.5 vulnerable to authorization header leak on port redirect","details":"**Summary**\n\nMechanize (rubygem) `\u003c v2.8.5` leaks the `Authorization` header after a redirect to a different port on the same site.\n\n**Mitigation**\n\nUpgrade to Mechanize v2.8.5 or later.\n\n**Notes**\n\nSee [https://curl.se/docs/CVE-2022-27776.html](CVE-2022-27776) for a similar vulnerability in curl.\n\nCookies are shared with a server at a different port on the same site, per https://datatracker.ietf.org/doc/html/rfc6265#section-8.5 which states in part:\n\n\u003e Cookies do not provide isolation by port.  If a cookie is readable\n\u003e by a service running on one port, the cookie is also readable by a\n\u003e service running on another port of the same server.  If a cookie is\n\u003e writable by a service on one port, the cookie is also writable by a\n\u003e service running on another port of the same server.  For this\n\u003e reason, servers SHOULD NOT both run mutually distrusting services on\n\u003e different ports of the same host and use cookies to store security-\n\u003e sensitive information.\n","aliases":["CVE-2022-31033"],"modified":"2023-11-08T04:09:23.331413Z","published":"2022-06-09T23:47:57Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-06-09T23:47:57Z","nvd_published_at":"2022-06-09T20:15:00Z","cwe_ids":["CWE-200","CWE-522"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/sparklemotion/mechanize/security/advisories/GHSA-64qm-hrgp-pgr9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31033"},{"type":"WEB","url":"https://github.com/sparklemotion/mechanize/commit/c7fe6996a5b95f9880653ba3bc548a8d4ef72317"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/mechanize/CVE-2022-31033.yml"},{"type":"PACKAGE","url":"https://github.com/sparklemotion/mechanize"}],"affected":[{"package":{"name":"mechanize","ecosystem":"RubyGems","purl":"pkg:gem/mechanize"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.8.5"}]}],"versions":["0.1.0","0.1.1","0.1.2","0.1.3","0.2.0","0.2.1","0.2.2","0.2.3","0.3.0","0.3.1","0.4.0","0.4.1","0.4.2","0.4.3","0.4.4","0.4.5","0.4.6","0.4.7","0.5.0","0.5.1","0.5.2","0.5.3","0.5.4","0.6.0","0.6.1","0.6.10","0.6.11","0.6.2","0.6.3","0.6.4","0.6.5","0.6.6","0.6.7","0.6.8","0.6.9","0.7.0","0.7.1","0.7.2","0.7.3","0.7.4","0.7.5","0.7.6","0.7.7","0.7.8","0.8.0","0.8.1","0.8.2","0.8.3","0.8.4","0.8.5","0.9.0","0.9.1","0.9.2","0.9.3","1.0.0","1.0.1.beta.20110107104205","2.0","2.0.1","2.0.pre.1","2.0.pre.2","2.1","2.1.1","2.1.pre.1","2.2","2.2.1","2.3","2.4","2.5","2.5.1","2.6.0","2.7.0","2.7.1","2.7.2","2.7.3","2.7.4","2.7.5","2.7.6","2.7.7","2.8.0","2.8.1","2.8.2","2.8.3","2.8.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-64qm-hrgp-pgr9/GHSA-64qm-hrgp-pgr9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}