Lack of data validation In cgi
Description
HTTP response splitting in CGI Ruby gem cgi.rb prior to versions 0.3.5, 0.2.2 and 0.1.0.2 allow HTTP header injection. If a CGI application using the CGI library inserts untrusted input into the HTTP response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. This issue has been patched in versions 0.3.5, 0.2.2 and 0.1.0.2.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rubygems | 0.3.5, 0.2.2, 0.1.0.2 | ||
debian 12 | 3.1.2-4 | ||
alpine v3.21 | 3.1.3-r0 | ||
alpine v3.22 | 3.1.3-r0 | ||
alpine v3.14 | 2.7.7-r0 | ||
alpine v3.15 | 3.0.5-r0 | ||
alpine v3.16 | 3.1.3-r0 | ||
alpine v3.17 | 3.1.3-r0 | ||
alpine v3.18 | 3.1.3-r0 | ||
alpine v3.19 | 3.1.3-r0 |
1-10 of 19
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13.