VDB
Sign up
HIGH7.5

GHSA-4vf4-qmvg-mh7h

Cookie Prefix Spoofing in CGI::Cookie.parse

Quick fix

GHSA-4vf4-qmvg-mh7h — cgi: upgrade to the fixed version with the command below.

bundle update cgi

Details

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem prior to versions 0.3.1, 0.2.1, 0.1.1, and 0.1.0.1 for Ruby.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/cgi
Introduced in: 0.3.0Fixed in: 0.3.1
Fixbundle update cgi
RubyGems/cgi
Introduced in: 0.2.0Fixed in: 0.2.1
Fixbundle update cgi
RubyGems/cgi
Introduced in: 0Fixed in: 0.1.0.1
Fixbundle update cgi

References