VDB
Sign up
MEDIUM

GHSA-8cgq-6mh2-7j6v

Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection

Quick fix

GHSA-8cgq-6mh2-7j6v — rack: upgrade to the fixed version with the command below.

bundle update rack

Details

## Summary

`Rack::Sendfile` can be exploited by crafting input that includes newline characters to manipulate log entries.

## Details

The `Rack::Sendfile` middleware logs unsanitized header values from the `X-Sendfile-Type` header. An attacker can exploit this by injecting escape sequences (such as newline characters) into the header, resulting in log injection.

## Impact

This vulnerability can distort log files, obscure attack traces, and complicate security auditing.

## Mitigation

- Update to the latest version of Rack, or - Remove usage of `Rack::Sendfile`.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rack
Introduced in: 0Fixed in: 2.2.12
Fixbundle update rack
RubyGems/rack
Introduced in: 3.0Fixed in: 3.0.13
Fixbundle update rack
RubyGems/rack
Introduced in: 3.1Fixed in: 3.1.11
Fixbundle update rack

References