Vulnerability Details CVE-2013-7134
Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by leveraging the secret key in app/config/initializers/secret_token.rb, related to cookies.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 65.8%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2013-7134
-
cpe:2.3:a:phusion:juvia:-