ZeroHour

CVE-2021-33621

PoC
CVSS 3.1
8.8 high
EPSS
2%p83
Published
()
Modified
Description

The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.

Vendors
ruby-langfedoraproject
Products
cgi, fedora, ruby
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.