Launch Week Day 1: Announcing Security Design Review
HIGH 8.8 RubyGems

HTTP response splitting in CGI

GHSA-vc47-6rqg-c7f5 · BIT-ruby-2021-33621 · BIT-ruby-min-2021-33621 · CVE-2021-33621

Published · Modified

Description

Ruby gem cgi.rb prior to versions 0.3.5, 0.2.2 and 0.1.0.2 allow HTTP header injection. If a CGI application using the CGI library inserts untrusted input into the HTTP response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. This issue has been patched in versions 0.3.5, 0.2.2 and 0.1.0.2.

Ready to move

Start Securing

Free, no credit card | First findings in minutes