|
oss-sec
mailing list archives
Ruby 3.0.10 WEBrick::HTTPRequest X-Forwarded-*
From: Kurt Seifried <kseifried () redhat com>
Date: Wed, 12 Oct 2011 13:06:10 -0600
Various methods in WEBrick::HTTPRequest in Ruby on Rails 3.0.10 do not
validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Server
headers in requests, which might allow remote attackers to inject
arbitrary text into log files or bypass intended address parsing via a
crafted header.
https://redmine.ruby-lang.org/issues/5418
Can we get a CVE for this please?
-Kurt Seifried / Red Hat Security Response Team
By Date
By Thread
Current thread:
Re: radvd 1.8.2 released with security fixes Huzaifa Sidhpurwala (Oct 13)
|