HIGH 7.5 RubyGems

WEBRick vulnerable to HTTP Request/Response Smuggling

GHSA-gwfg-cqmg-cf8f · BIT-ruby-2020-25613 · BIT-ruby-min-2020-25613 · CVE-2020-25613

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issue to bypass a reverse proxy (which also has a poor header check), which may lead to an HTTP Request Smuggling attack.

Ready to move

Start Securing

Free, no credit card | First findings in minutes