GHSA-fcqf-h4h4-695m

Suggest an improvement
Source
https://github.com/advisories/GHSA-fcqf-h4h4-695m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-fcqf-h4h4-695m/GHSA-fcqf-h4h4-695m.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-fcqf-h4h4-695m
Aliases
Published
2017-10-24T18:33:38Z
Modified
2024-12-05T05:27:27.352808Z
Summary
actionpack CRLF injection vulnerability
Details

CRLF injection vulnerability in actionpack/lib/action_controller/response.rb in Ruby on Rails 2.3.x before 2.3.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the Content-Type header.

Database specific
{
    "nvd_published_at": "2011-08-29T18:55:01Z",
    "cwe_ids": [
        "CWE-94"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-16T21:34:21Z"
}
References

Affected packages

RubyGems / actionpack

Package

Name
actionpack
Purl
pkg:gem/actionpack

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.3.0
Fixed
2.3.13

Affected versions

2.*

2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8.pre1
2.3.8
2.3.9.pre
2.3.9
2.3.10
2.3.11
2.3.12