CVE-2011-3187
actionpack Improper Input Validation vulnerability
EPSS 6.7%
描述
The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from IP addresses on a Class C network, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.
如何修補 CVE-2011-3187
要修補 CVE-2011-3187,請將受影響套件升級到下列已修補版本。
- Debian/rails—未列出修補版本
- RubyGems/actionpack—升級至 2.3.13 或更新版本
CVE-2011-3187 正在被利用嗎?
中等 — EPSS 為 6.7%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0
- >= 2.3.0, < 2.3.13