Описание
agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenStack Foreman | ruby193-rubygem-passenger | Will not fix | ||
| OpenStack Foreman | rubygem-passenger | Will not fix | ||
| Red Hat Ceph Storage 1.3 | ruby193-rubygem-passenger | Will not fix | ||
| Red Hat Ceph Storage 1.3 | rubygem-passenger | Will not fix | ||
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installer | ruby193-rubygem-passenger | Will not fix | ||
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installer | rubygem-passenger | Will not fix | ||
| Red Hat OpenShift Enterprise 2 | ruby193-rubygem-passenger | Will not fix | ||
| Red Hat OpenShift Enterprise 2 | ruby200-rubygem-passenger | Will not fix | ||
| Red Hat OpenShift Enterprise 2 | rubygem-passenger | Will not fix | ||
| Red Hat Satellite 6 | rubygem-passenger | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.8 Medium
CVSS2
Связанные уязвимости
agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.
agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.
agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0. ...
Phusion Passenger allows remote attackers to spoof headers
EPSS
5.8 Medium
CVSS2