{ "canonical_id": "rails--CVE-2009-3086", "system_id": "rails", "title": "CVE-2009-3086", "reasons": [ "missing affected/fixed version details" ], "candidate_count": 1, "references": [ "http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html", "http://secunia.com/advisories/36600", "http://weblog.rubyonrails.org/2009/9/4/timing-weakness-in-ruby-on-rails", "http://www.debian.org/security/2011/dsa-2260", "http://www.securityfocus.com/bid/37427", "http://www.vupen.com/english/advisories/2009/2544" ] }