Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-41819

Опубликовано: 24 нояб. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

A flaw was found in Ruby. RubyGems cgi gem could allow a remote attacker to conduct spoofing attacks caused by the mishandling of security prefixes in cookie names in the CGI::Cookie.parse function. By sending a specially-crafted request, an attacker could perform cookie prefix spoofing attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6rubyOut of support scope
Red Hat Enterprise Linux 7rubyOut of support scope
Red Hat Enterprise Linux 9rubyNot affected
Red Hat Enterprise Linux 8rubyFixedRHSA-2022:054316.02.2022
Red Hat Enterprise Linux 8rubyFixedRHSA-2022:577901.08.2022
Red Hat Enterprise Linux 8rubyFixedRHSA-2022:644713.09.2022
Red Hat Enterprise Linux 8rubyFixedRHSA-2022:645013.09.2022
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsrubyFixedRHSA-2022:058121.02.2022
Red Hat Enterprise Linux 8.2 Extended Update SupportrubyFixedRHSA-2022:058221.02.2022
Red Hat Enterprise Linux 8.4 Extended Update SupportrubyFixedRHSA-2022:054416.02.2022

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2026757ruby: Cookie prefix spoofing in CGI::Cookie.parse

EPSS

Процентиль: 71%
0.00691
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

CVSS3: 7.5
nvd
больше 3 лет назад

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

CVSS3: 7.5
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 3 лет назад

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes i ...

suse-cvrf
почти 3 года назад

Security update for ruby2.5

EPSS

Процентиль: 71%
0.00691
Низкий

7.5 High

CVSS3