Skip to content

Commit ac4eb3b

Browse files
committed
Land rapid7#4578, @dlanner's fix for rails_secret_deserialization
2 parents 7876401 + c5cfc11 commit ac4eb3b

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

modules/exploits/multi/http/rails_secret_deserialization.rb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -234,7 +234,7 @@ def exploit
234234
'method' => datastore['HTTP_METHOD'],
235235
}, 25)
236236
if res && !res.get_cookies.empty?
237-
match = res.get_cookies.match(/([_A-Za-z0-9]+)=([A-Za-z0-9%]*)--([0-9A-Fa-f]+); /)
237+
match = res.get_cookies.match(/([_A-Za-z0-9]+)=([A-Za-z0-9%]*)--([0-9A-Fa-f]+);/)
238238
end
239239

240240
if match

0 commit comments

Comments
 (0)