Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fxwv-953p-7qpf

Опубликовано: 10 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 3.7

Описание

Phusion Passenger allows remote attackers to spoof headers

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.

Пакеты

Наименование

passenger

rubygems
Затронутые версииВерсия исправления

< 4.0.60

4.0.60

Наименование

passenger

rubygems
Затронутые версииВерсия исправления

>= 5.0.0, < 5.0.22

5.0.22

EPSS

Процентиль: 58%
0.00361
Низкий

3.7 Low

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 10 лет назад

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.

redhat
около 10 лет назад

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.

CVSS3: 3.7
nvd
около 10 лет назад

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.

CVSS3: 3.7
debian
около 10 лет назад

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0. ...

suse-cvrf
около 10 лет назад

Security update for rubygem-passenger

EPSS

Процентиль: 58%
0.00361
Низкий

3.7 Low

CVSS3

Дефекты

CWE-20