HIGH7.5
GHSA-6f62-3596-g6w7
HTTP Request Smuggling in ruby webrick
Quick fix
GHSA-6f62-3596-g6w7 — webrick: upgrade to the fixed version with the command below.
bundle update webrickDetails
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production."
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-47220[ADVISORY]
- https://github.com/ruby/webrick/issues/145[WEB]
- https://github.com/ruby/webrick/issues/145#issuecomment-2369994610[WEB]
- https://github.com/ruby/webrick/issues/145#issuecomment-2372838285[WEB]
- https://github.com/ruby/webrick/pull/146/commits/d88321da45dcd230ac2b4585cad4833d6d5e8841[WEB]
- https://github.com/ruby/webrick/commit/f5faca9222541591e1a7c3c97552ebb0c92733c7[WEB]
- https://github.com/ruby/webrick[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/webrick/CVE-2024-47220.yml[WEB]