ZeroHour

CVE-2021-41819

PoC
CVSS 3.1
7.5 high
EPSS
3%p86
Published
()
Modified
Description

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

Vendors
ruby-langredhatdebiansuseopensusefedoraproject
Products
cgi, ruby, software collections, enterprise linux, debian linux, linux enterprise, factory, leap, fedora
Weakness
CWE-565
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.