CVE-2011-3624: Medium severity ruby vulnerability
Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Server headers in requests, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2011-3624?
CVE-2011-3624 is a vulnerability in Ruby 1.9.2 and 1.8.7 and earlier versions that allows remote attackers to inject arbitrary text into log files or bypass intended address parsing.
What is the severity of CVE-2011-3624?
The severity of CVE-2011-3624 is medium with a CVSS score of 5.3.
How does CVE-2011-3624 affect Ruby?
CVE-2011-3624 affects Ruby versions 1.9.2 and 1.8.7 and earlier.
How can remote attackers exploit CVE-2011-3624?
Remote attackers can exploit CVE-2011-3624 by injecting arbitrary text into log files or bypassing intended address parsing.
Are there any known remedies for CVE-2011-3624?
No known remedies are available for CVE-2011-3624 at this time.