Server side template injection In ruby3.1
Description
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel8 | 0:2.5.9-115.module+el8.10.0+24408+7ffaaa88 | ||
rpm rhel9 | 0:3.0.7-167.el9_8 | ||
rpm rhel9.6 | 0:3.0.7-165.el9_6.1 | ||
rpm rhel10 | 0:4.0.3-35.el10_2 | ||
rubygems | 0.6.4, 0.5.14, 0.4.24 | ||
debian 14 | - | ||
debian 12 | - | ||
debian 13 | - | ||
rpm rhel10 | 0:3.3.10-13.el10_2 | ||
rpm rhel7 | - | - |
1-10 of 13
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18. 19. 20. 21. 22. 23. 24. 25. 26. 27. 28. 29. 30. 31.
References
1. 2. 3. 4. 5. 6. 7. 8. 9.