cbcvebase.
CVE-2021-41819
published 2022-01-01

CVE-2021-41819: CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianruby2.7< ruby2.7 2.7.4-1+deb11u1 (bullseye)ruby2.7 2.7.4-1+deb11u1 (bullseye)
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_ruby_3.1.2-2_on_cbl_mariner_2.0
opensuseleap
redhatenterprise_linux
ruby-langcgi
ruby-langcgi
ruby-langcgi
ruby-langcgi>= 0 < 0.1.0.10.1.0.1
ruby-langcgi>= 0.2.0 < 0.2.10.2.1
ruby-langcgi>= 0.3.0 < 0.3.10.3.1
ruby-langruby<= 2.6.8
ruby-langruby>= 2.7.0 < 2.7.52.7.5
ruby-langruby>= 3.0.0 < 3.0.33.0.3
suselinux_enterprise
suselinux_enterprise
suselinux_enterprise

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv9.8CRITICAL