CVE-2021-41819
published 2022-01-01CVE-2021-41819: CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
2.93%
85.5th percentile
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ruby2.7 | < ruby2.7 2.7.4-1+deb11u1 (bullseye) | ruby2.7 2.7.4-1+deb11u1 (bullseye) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_ruby_3.1.2-2_on_cbl_mariner_2.0 | — | — |
| opensuse | leap | — | — |
| redhat | enterprise_linux | — | — |
| ruby-lang | cgi | — | — |
| ruby-lang | cgi | — | — |
| ruby-lang | cgi | — | — |
| ruby-lang | cgi | >= 0 < 0.1.0.1 | 0.1.0.1 |
| ruby-lang | cgi | >= 0.2.0 < 0.2.1 | 0.2.1 |
| ruby-lang | cgi | >= 0.3.0 < 0.3.1 | 0.3.1 |
| ruby-lang | ruby | <= 2.6.8 | — |
| ruby-lang | ruby | >= 2.7.0 < 2.7.5 | 2.7.5 |
| ruby-lang | ruby | >= 3.0.0 < 3.0.3 | 3.0.3 |
| suse | linux_enterprise | — | — |
| suse | linux_enterprise | — | — |
| suse | linux_enterprise | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ruby vulnerabilities
vendor_ubuntu·2022-01-18·CVSS 9.8
CVE-2021-41816 [CRITICAL] Ruby vulnerabilities
Title: Ruby vulnerabilities
Summary: Several security issues were fixed in Ruby.
It was discovered that Ruby incorrectly handled certain HTML files.
An attacker could possibly use this issue to cause a crash. This
issue only affected Ubuntu 20.04 LTS, Ubuntu 21.04, and Ubuntu 21.10.
(CVE-2021-41816)
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a regular expression
denial of service. (CVE-2021-41817)
It was discovered that Ruby incorrectly handled certain cookie names.
An attacker could possibly use this issue to access or expose
sensitive information. (CVE-2021-41819)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
vendor_msrc·2022-01-11·CVSS 7.5
CVE-2021-41819 [HIGH] CWE-565 CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Custom
Red Hat
ruby: Cookie prefix spoofing in CGI::Cookie.parse
vendor_redhat·2021-11-24·CVSS 7.5
CVE-2021-41819 [HIGH] ruby: Cookie prefix spoofing in CGI::Cookie.parse
ruby: Cookie prefix spoofing in CGI::Cookie.parse
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
A flaw was found in Ruby. RubyGems cgi gem could allow a remote attacker to conduct spoofing attacks caused by the mishandling of security prefixes in cookie names in the CGI::Cookie.parse function. By sending a specially-crafted request, an attacker could perform cookie prefix spoofing attacks.
Package: ruby (Red Hat Enterprise Linux 6) - Out of support scope
Package: ruby (Red Hat Enterprise Linux 7) - Out of support scope
Package: ruby (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2021-41819: ruby2.7 - CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie n...
vendor_debian·2021·CVSS 7.5
CVE-2021-41819 [HIGH] CVE-2021-41819: ruby2.7 - CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie n...
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
Scope: local
bullseye: resolved (fixed in 2.7.4-1+deb11u1)
OSV
Cookie Prefix Spoofing in CGI::Cookie.parse
osv·2022-01-21
CVE-2021-41819 [HIGH] Cookie Prefix Spoofing in CGI::Cookie.parse
Cookie Prefix Spoofing in CGI::Cookie.parse
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem prior to versions 0.3.1, 0.2.1, 0.1.1, and 0.1.0.1 for Ruby.
GHSA
Cookie Prefix Spoofing in CGI::Cookie.parse
ghsa·2022-01-21
CVE-2021-41819 [HIGH] CWE-565 Cookie Prefix Spoofing in CGI::Cookie.parse
Cookie Prefix Spoofing in CGI::Cookie.parse
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem prior to versions 0.3.1, 0.2.1, 0.1.1, and 0.1.0.1 for Ruby.
OSV
ruby2.3, ruby2.5, ruby2.7 vulnerabilities
osv·2022-01-18·CVSS 9.8
CVE-2021-41816 [CRITICAL] ruby2.3, ruby2.5, ruby2.7 vulnerabilities
ruby2.3, ruby2.5, ruby2.7 vulnerabilities
It was discovered that Ruby incorrectly handled certain HTML files.
An attacker could possibly use this issue to cause a crash. This
issue only affected Ubuntu 20.04 LTS, Ubuntu 21.04, and Ubuntu 21.10.
(CVE-2021-41816)
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a regular expression
denial of service. (CVE-2021-41817)
It was discovered that Ruby incorrectly handled certain cookie names.
An attacker could possibly use this issue to access or expose
sensitive information. (CVE-2021-41819)
OSV
CVE-2021-41819: CGI::Cookie
osv·2022-01-01·CVSS 7.5
CVE-2021-41819 [HIGH] CVE-2021-41819: CGI::Cookie
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
No detection rules found.
No public exploits indexed.
HackerOne
Ruby CVE-2021-41819: Cookie Prefix Spoofing in CGI::Cookie.parse
hackerone·2022-02-03·CVSS 7.5
CVE-2021-41819 [HIGH] Ruby CVE-2021-41819: Cookie Prefix Spoofing in CGI::Cookie.parse
Ruby CVE-2021-41819: Cookie Prefix Spoofing in CGI::Cookie.parse
Release note: https://www.ruby-lang.org/en/news/2021/11/24/cookie-prefix-spoofing-in-cgi-cookie-parse-cve-2021-41819/
> The old versions of CGI::Cookie.parse applied URL decoding to cookie names. An attacker could exploit this vulnerability to spoof security prefixes in cookie names, which may be able to trick a vulnerable application.
> By this fix, CGI::Cookie.parse no longer decodes cookie names. Note that this is an incompatibility if cookie names that you are using include non-alphanumeric characters that are URL-encoded.
> This is the same issue of CVE-2020-8184.
---
The following is copied from hackerone's report. https://hackerone.com/reports/910552
I found the same problem with https://hackerone.com/reports/89
Bugzilla
CVE-2021-41819 ruby: Cookie prefix spoofing in CGI::Cookie.parse
bugzilla·2021-11-25·CVSS 7.5
CVE-2021-41819 [HIGH] CVE-2021-41819 ruby: Cookie prefix spoofing in CGI::Cookie.parse
CVE-2021-41819 ruby: Cookie prefix spoofing in CGI::Cookie.parse
The old versions of `CGI::Cookie.parse` applied URL decoding to cookie names. An attacker could exploit this vulnerability to spoof security prefixes in cookie names, which may be able to trick a vulnerable application. By this fix, `CGI::Cookie.parse` no longer decodes cookie names. Note that this is an incompatibility if cookie names that you are using include non-alphanumeric characters that are URL-encoded. This is the same issue of CVE-2020-8184.
Reference:
https://www.ruby-lang.org/en/news/2021/11/24/cookie-prefix-spoofing-in-cgi-cookie-parse-cve-2021-41819/
Discussion:
Created ruby tracking bugs for this issue:
Affects: fedora-all [bug 2026759]
Created ruby:2.5/ruby tracking bugs for this issue:
Affects: fedora
https://hackerone.com/reports/910552https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IUXQCH6FRKANCVZO2Q7D2SQX33FP3KWN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UTOJGS5IEFDK3UOO7IY4OTTFGHGLSWZF/https://security.gentoo.org/glsa/202401-27https://security.netapp.com/advisory/ntap-20220121-0003/https://www.ruby-lang.org/en/news/2021/11/24/cookie-prefix-spoofing-in-cgi-cookie-parse-cve-2021-41819/https://hackerone.com/reports/910552https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IUXQCH6FRKANCVZO2Q7D2SQX33FP3KWN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UTOJGS5IEFDK3UOO7IY4OTTFGHGLSWZF/https://security.gentoo.org/glsa/202401-27https://security.netapp.com/advisory/ntap-20220121-0003/https://www.ruby-lang.org/en/news/2021/11/24/cookie-prefix-spoofing-in-cgi-cookie-parse-cve-2021-41819/
2022-01-01
Published