CVE-2008-5189
EPSS 0.13%rails is vulnerable to CRLF injection
發布日:2017/10/24修改日:2026/4/28
描述
CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL to the redirect_to function.
受影響套件(2)
- Debian/railsfrom 0, < 2.1.0-6
- RubyGems/railsfrom 0, < 2.0.5
參考連結(8)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2008-5189
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2008-5189
- PATCHhttp://github.com/rails/rails
- WEBhttp://github.com/rails/rails/commit/7282ed863ca7e6f928bae9162c9a63a98775a19d
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.html
- WEBhttps://github.com/rubysec/ruby-advisory-db/blob/master/gems/rails/CVE-2008-5189.yml
- WEBhttp://weblog.rubyonrails.org/2008/10/19/rails-2-0-5-redirect_to-and-offset-limit-sanitizing
- WEBhttp://weblog.rubyonrails.org/2008/10/19/response-splitting-risk