Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-7519

Опубликовано: 08 янв. 2016
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3
CVSS3: 3.7

Описание

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.

РелизСтатусПримечание
devel

not-affected

5.0.22-1
esm-apps/xenial

not-affected

5.0.22-1
esm-infra-legacy/trusty

DNE

precise

released

2.2.11debian-2+deb6u1ubuntu12.04.1
trusty

DNE

trusty/esm

DNE

upstream

released

5.0.22-1
vivid

DNE

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

Показывать по

4.3 Medium

CVSS2

3.7 Low

CVSS3

Связанные уязвимости

redhat
около 10 лет назад

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.

CVSS3: 3.7
nvd
около 10 лет назад

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.

CVSS3: 3.7
debian
около 10 лет назад

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0. ...

suse-cvrf
около 10 лет назад

Security update for rubygem-passenger

CVSS3: 3.7
github
больше 7 лет назад

Phusion Passenger allows remote attackers to spoof headers

4.3 Medium

CVSS2

3.7 Low

CVSS3