CVE-2021-41819

7.5HIGH

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

Published: 1/1/2022Updated: 5/22/2025

Description

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

AI AnalysisPowered by AI

Affected Products

ruby-langcgi
0.1.0
ruby-langcgi
0.2.0
ruby-langcgi
0.3.0
ruby-langruby
ruby-langruby
ruby-langruby
redhatsoftware_collections
-
redhatenterprise_linux
8.0
debiandebian_linux
9.0
debiandebian_linux
10.0
debiandebian_linux
11.0
suselinux_enterprise
11.0
suselinux_enterprise
12.0
suselinux_enterprise
15.0
opensusefactory
-
opensuseleap
15.2
fedoraprojectfedora
34
fedoraprojectfedora
35

References