VDB
EN
HIGH 8.8

GHSA-vc47-6rqg-c7f5

HTTP response splitting in CGI

빠른 조치

GHSA-vc47-6rqg-c7f5 — cgi: 아래 명령으로 수정 버전으로 올리세요.

bundle update cgi

상세

Ruby gem cgi.rb prior to versions 0.3.5, 0.2.2 and 0.1.0.2 allow HTTP header injection. If a CGI application using the CGI library inserts untrusted input into the HTTP response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. This issue has been patched in versions 0.3.5, 0.2.2 and 0.1.0.2.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

RubyGems / cgi
최초 영향 버전: 0.3.0 수정 버전: 0.3.5
수정 bundle update cgi
RubyGems / cgi
최초 영향 버전: 0.2.0 수정 버전: 0.2.2
수정 bundle update cgi
RubyGems / cgi
최초 영향 버전: 0 수정 버전: 0.1.0.2
수정 bundle update cgi

참고