Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 9: 2024-0348 critical: ruby-webrick HTTP request smuggling

mageia
Calendar Grey November 8, 2024
Dist Mageia Esm H88
Debian patches resolve the glibc memory leak vulnerability, bolstering runtime security and maintaining application performance.
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby

Summary

An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. (CVE-2024-47220)

References

- https://bugs.mageia.org/show_bug.cgi?id=33617

- https://ubuntu.com/security/notices/USN-7057-1

- https://www.cve.org/CVERecord?id=CVE-2024-47220

Resolution

SRPMS

- 9/core/ruby-webrick-1.7.0-3.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 08 Nov 2024
URL: https://advisories.mageia.org/MGASA-2024-0348.html
Type: security
CVE: CVE-2024-47220

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here