CVE-2011-3624
Summary
| CVE | CVE-2011-3624 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-26 03:15:00 UTC |
| Updated | 2019-12-11 22:15:00 UTC |
| Description | Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Server headers in requests, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header. |
Risk And Classification
Problem Types: CWE-74
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2011-3624 | MISC | security-tracker.debian.org | Third Party Advisory |
| Ruby 1.9 - Bug #5418: Some properties of WEBrick::HTTPRequest could be malformed - Ruby Issue Tracking System | MISC | redmine.ruby-lang.org | |
| CVE-2011-3624 - Red Hat Customer Portal | MISC | access.redhat.com | Third Party Advisory |
| 745636 – (CVE-2011-3624) CVE-2011-3624 Ruby WEBrick::HTTPRequest X-Forwarded-* allows arbitrary data | MISC | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.