CVE-2021-41263 is a high-severity vulnerability affecting Rails applications utilizing the rails_multisite gem for multi-database support, specifically when combined with Rails' signed/encrypted cookies. An attacker could potentially reuse cookies across different sites within a multi-site application, leading to unauthorized access, data compromise, and service disruption. The vulnerability has a CVSS score of 8.8 (High) due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, organizations using affected versions should upgrade to rails_multisite v4 to mitigate the risk, noting that this will invalidate previous cookies.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.0CPE matchmatch criteria | cpe:2.3:a:discourse:rails_multisite:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.