Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fcqf-h4h4-695m

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

actionpack CRLF injection vulnerability

CRLF injection vulnerability in actionpack/lib/action_controller/response.rb in Ruby on Rails 2.3.x before 2.3.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the Content-Type header.

Пакеты

Наименование

actionpack

rubygems
Затронутые версииВерсия исправления

>= 2.3.0, < 2.3.13

2.3.13

EPSS

Процентиль: 74%
0.00814
Низкий

Дефекты

CWE-94

Связанные уязвимости

ubuntu
больше 14 лет назад

CRLF injection vulnerability in actionpack/lib/action_controller/response.rb in Ruby on Rails 2.3.x before 2.3.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the Content-Type header.

nvd
больше 14 лет назад

CRLF injection vulnerability in actionpack/lib/action_controller/response.rb in Ruby on Rails 2.3.x before 2.3.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the Content-Type header.

debian
больше 14 лет назад

CRLF injection vulnerability in actionpack/lib/action_controller/respo ...

EPSS

Процентиль: 74%
0.00814
Низкий

Дефекты

CWE-94