VDB
Sign up
HIGH7.5

GHSA-6f62-3596-g6w7

HTTP Request Smuggling in ruby webrick

Quick fix

GHSA-6f62-3596-g6w7 — webrick: upgrade to the fixed version with the command below.

bundle update webrick

Details

An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production."

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/webrick
Introduced in: 0Fixed in: 1.8.2
Fixbundle update webrick

References