MEDIUM
GHSA-3vfw-7rcp-3xgm
actionpack Improper Input Validation vulnerability
상세
The `to_s` method in `actionpack/lib/action_dispatch/middleware/remote_ip.rb` in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from IP addresses on a Class C network, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
참고
- https://nvd.nist.gov/vuln/detail/CVE-2011-3187 [ADVISORY]
- https://bugzilla.novell.com/show_bug.cgi?id=673010 [WEB]
- https://github.com/rails/rails [PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionpack/CVE-2011-3187.yml [WEB]
- https://web.archive.org/web/20111209181000/http://archives.neohapsis.com/archives/fulldisclosure/2011-02/0337.html [WEB]
- http://webservsec.blogspot.com/2011/02/ruby-on-rails-vulnerability.html [WEB]
- http://www.openwall.com/lists/oss-security/2011/08/17/1 [WEB]
- http://www.openwall.com/lists/oss-security/2011/08/19/11 [WEB]
- http://www.openwall.com/lists/oss-security/2011/08/20/1 [WEB]
- http://www.openwall.com/lists/oss-security/2011/08/22/13 [WEB]
- http://www.openwall.com/lists/oss-security/2011/08/22/14 [WEB]
- http://www.openwall.com/lists/oss-security/2011/08/22/5 [WEB]