VDB
Sign up
LOW3.7

GHSA-fxwv-953p-7qpf

Phusion Passenger allows remote attackers to spoof headers

Quick fix

GHSA-fxwv-953p-7qpf — passenger: upgrade to the fixed version with the command below.

bundle update passenger

Details

`agent/Core/Controller/SendRequest.cpp` in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an `_` (underscore) character instead of a `-` (dash) character in an HTTP header, as demonstrated by an `X_User` header.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/passenger
Introduced in: 0Fixed in: 4.0.60
Fixbundle update passenger
RubyGems/passenger
Introduced in: 5.0.0Fixed in: 5.0.22
Fixbundle update passenger

References