VDB
Sign up
MEDIUM6.5

GHSA-7g2v-jj9q-g3rg

Possible Log Injection in Rack::CommonLogger

Quick fix

GHSA-7g2v-jj9q-g3rg — rack: upgrade to the fixed version with the command below.

bundle update rack

Details

## Summary

`Rack::CommonLogger` can be exploited by crafting input that includes newline characters to manipulate log entries. The supplied proof-of-concept demonstrates injecting malicious content into logs.

## Details

When a user provides the authorization credentials via `Rack::Auth::Basic`, if success, the username will be put in `env['REMOTE_USER']` and later be used by `Rack::CommonLogger` for logging purposes.

The issue occurs when a server intentionally or unintentionally allows a user creation with the username contain CRLF and white space characters, or the server just want to log every login attempts. If an attacker enters a username with CRLF character, the logger will log the malicious username with CRLF characters into the logfile.

## Impact

Attackers can break log formats or insert fraudulent entries, potentially obscuring real activity or injecting malicious data into log files.

## Mitigation

- Update to the latest version of Rack.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rack
Introduced in: 0Fixed in: 2.2.11
Fixbundle update rack
RubyGems/rack
Introduced in: 3.0Fixed in: 3.0.12
Fixbundle update rack
RubyGems/rack
Introduced in: 3.1Fixed in: 3.1.10
Fixbundle update rack

References