CVE-2011-3187
published 2011-08-29CVE-2011-3187: The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from…
PriorityP431medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
6.67%
93.2th percentile
The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from IP addresses on a Class C network, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actionpack_project | actionpack | >= 2.3.0 < 2.3.13 | 2.3.13 |
| debian | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2011-3187: rails - The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Rub...
vendor_debian·2011·CVSS 4.3
CVE-2011-3187 [MEDIUM] CVE-2011-3187: rails - The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Rub...
The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from IP addresses on a Class C network, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
actionpack Improper Input Validation vulnerability
ghsa·2017-10-24
CVE-2011-3187 [MEDIUM] CWE-20 actionpack Improper Input Validation vulnerability
actionpack Improper Input Validation vulnerability
The `to_s` method in `actionpack/lib/action_dispatch/middleware/remote_ip.rb` in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from IP addresses on a Class C network, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.
OSV
actionpack Improper Input Validation vulnerability
osv·2017-10-24
CVE-2011-3187 [MEDIUM] actionpack Improper Input Validation vulnerability
actionpack Improper Input Validation vulnerability
The `to_s` method in `actionpack/lib/action_dispatch/middleware/remote_ip.rb` in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from IP addresses on a Class C network, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.
OSV
CVE-2011-3187: The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip
osv·2011-08-29·CVSS 4.3
CVE-2011-3187 [MEDIUM] CVE-2011-3187: The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip
The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from IP addresses on a Class C network, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.
No detection rules found.
http://archives.neohapsis.com/archives/fulldisclosure/2011-02/0337.htmlhttp://webservsec.blogspot.com/2011/02/ruby-on-rails-vulnerability.htmlhttp://www.openwall.com/lists/oss-security/2011/08/17/1http://www.openwall.com/lists/oss-security/2011/08/19/11http://www.openwall.com/lists/oss-security/2011/08/20/1http://www.openwall.com/lists/oss-security/2011/08/22/13http://www.openwall.com/lists/oss-security/2011/08/22/14http://www.openwall.com/lists/oss-security/2011/08/22/5https://bugzilla.novell.com/show_bug.cgi?id=673010http://archives.neohapsis.com/archives/fulldisclosure/2011-02/0337.htmlhttp://webservsec.blogspot.com/2011/02/ruby-on-rails-vulnerability.htmlhttp://www.openwall.com/lists/oss-security/2011/08/17/1http://www.openwall.com/lists/oss-security/2011/08/19/11http://www.openwall.com/lists/oss-security/2011/08/20/1http://www.openwall.com/lists/oss-security/2011/08/22/13http://www.openwall.com/lists/oss-security/2011/08/22/14http://www.openwall.com/lists/oss-security/2011/08/22/5https://bugzilla.novell.com/show_bug.cgi?id=673010
2011-08-29
Published