Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 11

Количество 11

ubuntu логотип

CVE-2025-6442

около 1 года назад

Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2025-6442

около 1 года назад

Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-6442

около 1 года назад

Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2025-6442

около 1 года назад

Ruby WEBrick read_header HTTP Request Smuggling Vulnerability

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-6442

около 1 года назад

Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vu ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-r995-q44h-hr64

около 1 года назад

Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2025-10911

почти 3 года назад

Уязвимость функции read_headers() набора инструментов HTTP-сервера WEBrick, позволяющая нарушителю осуществлять атаки с подменой HTTP-запросов

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02739-2

11 месяцев назад

Security update for ruby2.5

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02739-1

12 месяцев назад

Security update for ruby2.5

EPSS: Низкий
redos логотип

ROS-20250826-03

11 месяцев назад

Множественные уязвимости rubygem-webrick

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4264-1

8 месяцев назад

Security update for ruby2.5

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-6442

Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.

CVSS3: 5.9
0%
Низкий
около 1 года назад
redhat логотип
CVE-2025-6442

Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.

CVSS3: 6.5
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-6442

Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.

CVSS3: 5.9
0%
Низкий
около 1 года назад
msrc логотип
CVE-2025-6442

Ruby WEBrick read_header HTTP Request Smuggling Vulnerability

CVSS3: 6.5
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-6442

Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vu ...

CVSS3: 5.9
0%
Низкий
около 1 года назад
github логотип
GHSA-r995-q44h-hr64

Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling

CVSS3: 6.5
0%
Низкий
около 1 года назад
fstec логотип
BDU:2025-10911

Уязвимость функции read_headers() набора инструментов HTTP-сервера WEBrick, позволяющая нарушителю осуществлять атаки с подменой HTTP-запросов

CVSS3: 5.9
0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2025:02739-2

Security update for ruby2.5

11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02739-1

Security update for ruby2.5

12 месяцев назад
redos логотип
ROS-20250826-03

Множественные уязвимости rubygem-webrick

CVSS3: 7.5
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4264-1

Security update for ruby2.5

8 месяцев назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.