Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6f62-3596-g6w7

Опубликовано: 22 сент. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

HTTP Request Smuggling in ruby webrick

An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production."

Пакеты

Наименование

webrick

rubygems
Затронутые версииВерсия исправления

<= 1.8.1

1.8.2

EPSS

Процентиль: 32%
0.00119
Низкий

7.5 High

CVSS3

Дефекты

CWE-444

Связанные уязвимости

ubuntu
12 месяцев назад

An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production."

CVSS3: 7.5
redhat
12 месяцев назад

An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production."

nvd
12 месяцев назад

An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production."

debian
12 месяцев назад

An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. ...

suse-cvrf
10 месяцев назад

Security update for ruby2.1

EPSS

Процентиль: 32%
0.00119
Низкий

7.5 High

CVSS3

Дефекты

CWE-444