Описание
Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs unsanitised header values from the X-Sendfile-Type header. An attacker can exploit this by injecting escape sequences (such as newline characters) into the header, resulting in log injection. This vulnerability is fixed in 2.2.12, 3.0.13, and 3.1.11.
A flaw was found in Rack Rubygem, where the Rack::Sendfile middleware logs unsanitized header values from the X-Sendfile-Type header. This flaw allows an attacker to inject escape sequences, such as newline characters, into the header, resulting in log injection.
Меры по смягчению последствий
To mitigate this vulnerability, remove usage of Rack::Sendfile.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Logging Subsystem for Red Hat OpenShift | openshift-logging/fluentd-rhel8 | Will not fix | ||
Red Hat 3scale API Management Platform 2 | 3scale-amp-zync-container | Affected | ||
Red Hat Enterprise Linux 7 | pcs | Out of support scope | ||
Red Hat Enterprise Linux 8 | pcs | Out of support scope | ||
Red Hat Enterprise Linux 9 | ruby-30 | Affected | ||
Red Hat Enterprise Linux 9 | ruby-31 | Affected | ||
Red Hat Enterprise Linux 9 | ruby-33 | Affected | ||
Red Hat Satellite 6 | rubygem-rack | Fix deferred | ||
Red Hat Satellite 6 | satellite-capsule:el8/rubygem-rack | Affected | ||
Red Hat Satellite 6 | satellite:el8/rubygem-rack | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
5.3 Medium
CVSS3
Связанные уязвимости
Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs unsanitised header values from the X-Sendfile-Type header. An attacker can exploit this by injecting escape sequences (such as newline characters) into the header, resulting in log injection. This vulnerability is fixed in 2.2.12, 3.0.13, and 3.1.11.
Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs unsanitised header values from the X-Sendfile-Type header. An attacker can exploit this by injecting escape sequences (such as newline characters) into the header, resulting in log injection. This vulnerability is fixed in 2.2.12, 3.0.13, and 3.1.11.
Rack is a modular Ruby web server interface. The Rack::Sendfile middle ...
5.3 Medium
CVSS3