Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-41819

Опубликовано: 01 янв. 2022
Источник: debian
EPSS Низкий

Описание

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby3.0fixed3.0.3-1package
ruby2.7fixed2.7.5-1package
ruby2.5removedpackage
ruby2.3removedpackage

Примечания

  • Fixed in Ruby 3.0.3, 2.7.5, 2.6.9

  • https://www.ruby-lang.org/en/news/2021/11/24/cookie-prefix-spoofing-in-cgi-cookie-parse-cve-2021-41819/

  • Fixed by: https://github.com/ruby/cgi/commit/052eb3a828b0f99bca39cfd800f6c2b91307dbd5 (v0.3.1)

EPSS

Процентиль: 71%
0.00691
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

CVSS3: 7.5
redhat
больше 3 лет назад

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

CVSS3: 7.5
nvd
больше 3 лет назад

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

CVSS3: 7.5
msrc
больше 3 лет назад

Описание отсутствует

suse-cvrf
почти 3 года назад

Security update for ruby2.5

EPSS

Процентиль: 71%
0.00691
Низкий