oss-sec mailing list archives

Ruby 1.9.2-p290 WEBrick::HTTPRequest X-Forwarded-*


From: Kurt Seifried <kseifried () redhat com>
Date: Wed, 12 Oct 2011 15:37:29 -0600

Got my Ruby/Ruby on rails mixed up.

Various methods in WEBrick::HTTPRequest in Ruby 1.9.2-p290 and
1.8.7-p352 and earlier and do not validate the X-Forwarded-For,
X-Forwarded-Host and X-Forwarded-Server headers in requests, which might
allow remote attackers to inject arbitrary text into log files or bypass
intended address parsing via a crafted header.

https://redmine.ruby-lang.org/issues/5418

Can we get a CVE for this please?

-Kurt Seifried / Red Hat Security Response Team


Current thread: