CVE-2017-17742
MEDIUM5.3EPSS 1.2%jruby - security update
發布日:2018/4/3修改日:2026/4/28
描述
Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 allows an HTTP Response Splitting attack. An attacker can inject a crafted key and value into an HTTP response for the HTTP server of WEBrick.
受影響套件(7)
- Alpine/rubyfrom 0, < 2.5.1-r0
- Debian/jrubyfrom 0, < 1.5.6-9+deb8u2
- Debian/jrubyfrom 0, < 1.7.26-1+deb9u2
- Debian/jrubyfrom 0, < 9.3.9.0+ds-1
- Debian/jrubyfrom 0, < 9.1.17.0-3+deb10u1
- Debian/ruby1.8from 0, < 1.8.7.358-7.1+deb7u6
- Debian/ruby1.9.1from 0, < 1.9.3.194-8.1+deb7u8
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |