CVE-2021-41819

7.5HIGH

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

发布于: 1/1/2022更新于: 5/22/2025

描述

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

AI分析AI驱动

受影响产品

ruby-langcgi
0.1.0
ruby-langcgi
0.2.0
ruby-langcgi
0.3.0
ruby-langruby
ruby-langruby
ruby-langruby
redhatsoftware_collections
-
redhatenterprise_linux
8.0
debiandebian_linux
9.0
debiandebian_linux
10.0
debiandebian_linux
11.0
suselinux_enterprise
11.0
suselinux_enterprise
12.0
suselinux_enterprise
15.0
opensusefactory
-
opensuseleap
15.2
fedoraprojectfedora
34
fedoraprojectfedora
35

参考资料