CVE-2011-3186Code Injection in Project Actionpack

CWE-94Code Injection7 documents6 sources
Severity
4.3MEDIUMNVD
EPSS
0.8%
top 25.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 29
Latest updateOct 24

Description

CRLF injection vulnerability in actionpack/lib/action_controller/response.rb in Ruby on Rails 2.3.x before 2.3.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the Content-Type header.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

Debianrubyonrails/rails< 2.3.14+3
NVDrubyonrails/rails7 versions+6
RubyGemsactionpack_project/actionpack2.3.02.3.13

Patches

🔴Vulnerability Details

4
GHSA
actionpack CRLF injection vulnerability2017-10-24
OSV
actionpack CRLF injection vulnerability2017-10-24
OSV
CVE-2011-3186: CRLF injection vulnerability in actionpack/lib/action_controller/response2011-08-29
CVEList
CVE-2011-3186: CRLF injection vulnerability in actionpack/lib/action_controller/response2011-08-29

📋Vendor Advisories

1
Debian
CVE-2011-3186: rails - CRLF injection vulnerability in actionpack/lib/action_controller/response.rb in ...2011

💬Community

1
Bugzilla
CVE-2011-3186 rubygem-actionpack: response splitting flaw2011-08-20
CVE-2011-3186 — Code Injection in Project Actionpack | cvebase