Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability
Vulnerability Description
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.
CVSS Information
N/A
Vulnerability Type
HTTP请求的解释不一致性(HTTP请求私运)
Vulnerability Title
Webrick 环境问题漏洞
Vulnerability Description
Webrick是The Ruby Programming Language开源的一个 HTTP 服务器工具包。 Webrick存在环境问题漏洞,该漏洞源于read_headers方法对HTTP标头终止符解析不一致,可能导致HTTP请求夹带攻击。
CVSS Information
N/A
Vulnerability Type
N/A