Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-33621

Опубликовано: 18 нояб. 2022
Источник: redhat
CVSS3: 8.8

Описание

The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.

A vulnerability was found in Ruby that allows HTTP header injection. A CGI application using the CGI library may insert untrusted input into the HTTP response header. This issue can allow an attacker to insert a newline character to split a header and inject malicious content to deceive clients.

Отчет

This vulnerability is marked as moderate because the flaw was more difficult to exploit but could still lead to some compromise of the confidentiality, integrity, or availability of resources under certain circumstances but are less easily exploited based on a technical evaluation of the flaw, or affect unlikely configurations.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6rubyOut of support scope
Red Hat Enterprise Linux 7rubyOut of support scope
Red Hat Software Collectionsrh-ruby30-rubyWill not fix
Red Hat Enterprise Linux 8rubyFixedRHSA-2023:382127.06.2023
Red Hat Enterprise Linux 8rubyFixedRHSA-2023:702514.11.2023
Red Hat Enterprise Linux 8rubyFixedRHSA-2024:143119.03.2024
Red Hat Enterprise Linux 8rubyFixedRHSA-2024:350030.05.2024
Red Hat Enterprise Linux 9rubyFixedRHSA-2024:157601.04.2024
Red Hat Enterprise Linux 9rubyFixedRHSA-2024:383811.06.2024
Red Hat Enterprise Linux 9.2 Extended Update SupportrubyFixedRHSA-2024:454215.07.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-113
https://bugzilla.redhat.com/show_bug.cgi?id=2149706ruby/cgi-gem: HTTP response splitting in CGI

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 2 лет назад

The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.

CVSS3: 8.8
nvd
больше 2 лет назад

The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.

CVSS3: 8.8
debian
больше 2 лет назад

The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 ...

CVSS3: 8.8
github
больше 2 лет назад

HTTP response splitting in CGI

CVSS3: 8.8
fstec
больше 2 лет назад

Уязвимость компонента CGI языка программирования Ruby, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

8.8 High

CVSS3