CVE-2013-7134: Phusion Juvia

High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.

Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by leveraging the secret key in app/config/initializers/secret_token.rb, related to cookies.

Affected products

  • Phusion Juvia: affected versions not specified

Published 2014-04-29. Last modified 2026-06-17.