CVE-2015-1820: rubygem-rest-client: session fixation vulnerability Set-Cookie headers present in an HTTP 30x redirection responses

Severity: Critical

CVSS Score: 9.8

REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.