Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jmgf-p46x-982h

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

rails is vulnerable to CRLF injection

CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL to the redirect_to function.

Пакеты

Наименование

rails

rubygems
Затронутые версииВерсия исправления

< 2.0.5

2.0.5

EPSS

Процентиль: 39%
0.00169
Низкий

Дефекты

CWE-352

Связанные уязвимости

ubuntu
около 17 лет назад

CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL to the redirect_to function.

redhat
около 17 лет назад

CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL to the redirect_to function.

nvd
около 17 лет назад

CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL to the redirect_to function.

debian
около 17 лет назад

CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remo ...

EPSS

Процентиль: 39%
0.00169
Низкий

Дефекты

CWE-352