CVE-2020-5216: Limited header injection when using dynamic overrides with user input in RubyGems secure_headers
A directive injection vulnerability was found in Secure Headers RubyGem before versions 3.9.0, 5.2.0, and 6.3.0. If user-supplied input was passed into the vulnerable function, a new line could be injected, leading to limited header injection, which could create a new Content Security Policy header in the HTTP response.
Other sources
In Secure Headers (RubyGem secureheaders), a directive injection vulnerability is present in versions before 3.9.0, 5.2.0, and 6.3.0. If user-supplied input was passed into append/overridecontentsecuritypolicydirectives, a newline could be injected leading to limited header injection. Upon seeing a newline in the header, rails will silently create a new Content-Security-Policy header with the remaining value of the original string. It will continue to create new headers for each newline. This has been fixed in 6.3.0, 5.2.0, and 3.9.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/ansible-collection-redhat-satelliteto a version that resolves this vulnerability.Fixed in 0:1.3.0-1.el7 - Upgrade
Upgrade
redhat/ansiblerole-insights-clientto a version that resolves this vulnerability.Fixed in 0:1.7.1-1.el7 - Upgrade
Upgrade
redhat/ansiblerole-satellite-receptor-installerto a version that resolves this vulnerability.Fixed in 0:0.6.13-1.el7 - Upgrade
Upgrade
redhat/ansible-runnerto a version that resolves this vulnerability.Fixed in 0:1.4.6-1.el7a - Upgrade
Upgrade
redhat/candlepinto a version that resolves this vulnerability.Fixed in 0:3.1.21-1.el7 - Upgrade
Upgrade
redhat/foremanto a version that resolves this vulnerability.Fixed in 0:2.1.2.19-1.el7 - Upgrade
Upgrade
redhat/foreman-bootloaders-redhatto a version that resolves this vulnerability.Fixed in 0:202005201200-1.el7 - Upgrade
Upgrade
redhat/foreman-discovery-image-serviceto a version that resolves this vulnerability.Fixed in 0:1.0.0-3.el7 - Upgrade
Upgrade
redhat/foreman-installerto a version that resolves this vulnerability.Fixed in 1:2.1.2.8-1.el7 - Upgrade
Upgrade
redhat/foreman-proxyto a version that resolves this vulnerability.Fixed in 0:2.1.2-2.el7 - Upgrade
Upgrade
redhat/foreman-selinuxto a version that resolves this vulnerability.Fixed in 0:2.1.2.3-1.el7 - Upgrade
Upgrade
redhat/futureto a version that resolves this vulnerability.Fixed in 0:0.16.0-11.el7 - Upgrade
Upgrade
redhat/goferto a version that resolves this vulnerability.Fixed in 0:2.12.5-7.el7 - Upgrade
Upgrade
redhat/hfsplus-toolsto a version that resolves this vulnerability.Fixed in 0:332.14-12.el7 - Upgrade
Upgrade
redhat/katelloto a version that resolves this vulnerability.Fixed in 0:3.16.0-1.el7 - Upgrade
Upgrade
redhat/katello-certs-toolsto a version that resolves this vulnerability.Fixed in 0:2.7.1-1.el7 - Upgrade
Upgrade
redhat/katello-client-bootstrapto a version that resolves this vulnerability.Fixed in 0:1.7.5-1.el7 - Upgrade
Upgrade
redhat/katello-selinuxto a version that resolves this vulnerability.Fixed in 0:3.4.0-1.el7 - Upgrade
Upgrade
redhat/keycloak-httpd-client-installto a version that resolves this vulnerability.Fixed in 0:1.2.2-1.el7 - Upgrade
Upgrade
redhat/koboto a version that resolves this vulnerability.Fixed in 0:0.5.1-1.el7 - Upgrade
Upgrade
redhat/libmodulemdto a version that resolves this vulnerability.Fixed in 0:1.7.0-1.pulp.el7 - Upgrade
Upgrade
redhat/libsolvto a version that resolves this vulnerability.Fixed in 0:0.7.4-4.pulp.el7 - Upgrade
Upgrade
redhat/libwebsocketsto a version that resolves this vulnerability.Fixed in 0:2.4.2-2.el7 - Upgrade
Upgrade
redhat/livecd-toolsto a version that resolves this vulnerability.Fixed in 1:20.4-1.6.el7 - Upgrade
Upgrade
redhat/ostreeto a version that resolves this vulnerability.Fixed in 0:2017.1-2.atomic.el7 - Upgrade
Upgrade
redhat/pcp-mmvstatsdto a version that resolves this vulnerability.Fixed in 0:0.4-2.el7 - Upgrade
Upgrade
redhat/pulpto a version that resolves this vulnerability.Fixed in 0:2.21.3-1.el7 - Upgrade
Upgrade
redhat/pulp-dockerto a version that resolves this vulnerability.Fixed in 0:3.2.7-1.el7 - Upgrade
Upgrade
redhat/pulp-katelloto a version that resolves this vulnerability.Fixed in 0:1.0.3-1.el7 - Upgrade
Upgrade
redhat/pulp-ostreeto a version that resolves this vulnerability.Fixed in 0:1.3.1-2.el7 - Upgrade
Upgrade
redhat/pulp-puppetto a version that resolves this vulnerability.Fixed in 0:2.21.3-2.el7 - Upgrade
Upgrade
redhat/pulp-rpmto a version that resolves this vulnerability.Fixed in 0:2.21.3-2.el7 - Upgrade
Upgrade
redhat/puppet-agentto a version that resolves this vulnerability.Fixed in 0:6.14.0-2.el7 - Upgrade
Upgrade
redhat/puppet-agent-oauthto a version that resolves this vulnerability.Fixed in 0:0.5.1-3.el7 - Upgrade
Upgrade
redhat/puppetlabs-stdlibto a version that resolves this vulnerability.Fixed in 0:4.25.1-2.el7 - Upgrade
Upgrade
redhat/puppetserverto a version that resolves this vulnerability.Fixed in 0:6.13.0-1.el7 - Upgrade
Upgrade
redhat/pycairoto a version that resolves this vulnerability.Fixed in 0:1.16.3-9.el7 - Upgrade
Upgrade
redhat/pygobject3to a version that resolves this vulnerability.Fixed in 0:3.28.3-2.el7 - Upgrade
Upgrade
redhat/python-aiohttpto a version that resolves this vulnerability.Fixed in 0:3.6.2-4.el7a - Upgrade
Upgrade
redhat/python-amqpto a version that resolves this vulnerability.Fixed in 0:2.2.2-5.el7 - Upgrade
Upgrade
redhat/python-anyjsonto a version that resolves this vulnerability.Fixed in 0:0.3.3-11.el7 - Upgrade
Upgrade
redhat/python-apypieto a version that resolves this vulnerability.Fixed in 0:0.2.2-1.el7 - Upgrade
Upgrade
redhat/python-async-timeoutto a version that resolves this vulnerability.Fixed in 0:3.0.1-2.el7a - Upgrade
Upgrade
redhat/python-attrsto a version that resolves this vulnerability.Fixed in 0:19.3.0-3.el7a - Upgrade
Upgrade
redhat/python-billiardto a version that resolves this vulnerability.Fixed in 1:3.5.0.3-3.el7 - Upgrade
Upgrade
redhat/python-blinkerto a version that resolves this vulnerability.Fixed in 0:1.3-2.el7 - Upgrade
Upgrade
redhat/python-celeryto a version that resolves this vulnerability.Fixed in 0:4.0.2-9.el7 - Upgrade
Upgrade
redhat/python-chardetto a version that resolves this vulnerability.Fixed in 0:3.0.4-10.el7a - Upgrade
Upgrade
redhat/python-clickto a version that resolves this vulnerability.Fixed in 0:6.7-9.el7 - Upgrade
Upgrade
redhat/python-craneto a version that resolves this vulnerability.Fixed in 0:3.3.1-9.el7 - Upgrade
Upgrade
redhat/python-daemonto a version that resolves this vulnerability.Fixed in 0:2.1.2-7.el7a - Upgrade
Upgrade
redhat/python-dateutilto a version that resolves this vulnerability.Fixed in 0:2.8.1-2.el7a - Upgrade
Upgrade
redhat/python-djangoto a version that resolves this vulnerability.Fixed in 0:1.11.29-1.el7 - Upgrade
Upgrade
redhat/python-flaskto a version that resolves this vulnerability.Fixed in 1:0.12.2-4.el7 - Upgrade
Upgrade
redhat/python-gnupgto a version that resolves this vulnerability.Fixed in 0:0.3.7-1.el7 - Upgrade
Upgrade
redhat/python-idnato a version that resolves this vulnerability.Fixed in 0:2.4-2.el7a - Upgrade
Upgrade
redhat/python-idna-sslto a version that resolves this vulnerability.Fixed in 0:1.1.0-2.el7a - Upgrade
Upgrade
redhat/python-isodateto a version that resolves this vulnerability.Fixed in 0:0.5.4-12.el7 - Upgrade
Upgrade
redhat/python-itsdangerousto a version that resolves this vulnerability.Fixed in 0:0.24-15.el7 - Upgrade
Upgrade
redhat/python-jinja2to a version that resolves this vulnerability.Fixed in 0:2.10-10.el7 - Upgrade
Upgrade
redhat/python-jmespathto a version that resolves this vulnerability.Fixed in 0:0.9.0-6.el7_7 - Upgrade
Upgrade
redhat/python-kidto a version that resolves this vulnerability.Fixed in 0:0.9.6-11.el7 - Upgrade
Upgrade
redhat/python-kombuto a version that resolves this vulnerability.Fixed in 10:4.0.2-13.el7 - Upgrade
Upgrade
redhat/python-lockfileto a version that resolves this vulnerability.Fixed in 1:0.11.0-10.el7a - Upgrade
Upgrade
redhat/python-markupsafeto a version that resolves this vulnerability.Fixed in 0:0.23-21.el7 - Upgrade
Upgrade
redhat/python-mongoengineto a version that resolves this vulnerability.Fixed in 0:0.10.5-2.el7 - Upgrade
Upgrade
redhat/python-multidictto a version that resolves this vulnerability.Fixed in 0:4.7.4-2.el7a - Upgrade
Upgrade
redhat/python-nectarto a version that resolves this vulnerability.Fixed in 0:1.6.2-1.el7 - Upgrade
Upgrade
redhat/python-oauth2to a version that resolves this vulnerability.Fixed in 0:1.5.211-8.el7 - Upgrade
Upgrade
redhat/python-okaarato a version that resolves this vulnerability.Fixed in 0:1.0.37-2.el7 - Upgrade
Upgrade
redhat/python-pexpectto a version that resolves this vulnerability.Fixed in 0:4.6-1.el7a - Upgrade
Upgrade
redhat/python-prometheus-clientto a version that resolves this vulnerability.Fixed in 0:0.7.1-2.el7a - Upgrade
Upgrade
redhat/python-psutilto a version that resolves this vulnerability.Fixed in 0:5.0.1-3.el7 - Upgrade
Upgrade
redhat/python-ptyprocessto a version that resolves this vulnerability.Fixed in 0:0.5.2-3.el7a - Upgrade
Upgrade
redhat/python-pycurlto a version that resolves this vulnerability.Fixed in 0:7.43.0.2-4.el7 - Upgrade
Upgrade
redhat/python-pymongoto a version that resolves this vulnerability.Fixed in 0:3.2-2.el7 - Upgrade
Upgrade
redhat/python-qpidto a version that resolves this vulnerability.Fixed in 0:1.35.0-5.el7 - Upgrade
Upgrade
redhat/python-receptor-satelliteto a version that resolves this vulnerability.Fixed in 0:1.2.0-1.el7 - Upgrade
Upgrade
redhat/python-simplejsonto a version that resolves this vulnerability.Fixed in 0:3.2.0-1.el7 - Upgrade
Upgrade
redhat/python-sixto a version that resolves this vulnerability.Fixed in 0:1.11.0-8.el7a - Upgrade
Upgrade
redhat/python-twistedto a version that resolves this vulnerability.Fixed in 0:16.4.1-12.el7 - Upgrade
Upgrade
redhat/python-typing-extensionsto a version that resolves this vulnerability.Fixed in 0:3.7.4.1-2.el7a - Upgrade
Upgrade
redhat/python-vineto a version that resolves this vulnerability.Fixed in 10:1.1.3-6.el7 - Upgrade
Upgrade
redhat/python-werkzeugto a version that resolves this vulnerability.Fixed in 0:0.12.2-5.el7 - Upgrade
Upgrade
redhat/python-yarlto a version that resolves this vulnerability.Fixed in 0:1.4.2-2.el7a - Upgrade
Upgrade
redhat/python-zope-interfaceto a version that resolves this vulnerability.Fixed in 0:4.0.5-4.el7 - Upgrade
Upgrade
redhat/qpid-cppto a version that resolves this vulnerability.Fixed in 0:1.36.0-28.el7a - Upgrade
Upgrade
redhat/qpid-dispatchto a version that resolves this vulnerability.Fixed in 0:1.5.0-4.el7 - Upgrade
Upgrade
redhat/qpid-protonto a version that resolves this vulnerability.Fixed in 0:0.28.0-3.el7 - Upgrade
Upgrade
redhat/receptorto a version that resolves this vulnerability.Fixed in 0:0.6.3-1.el7a - Upgrade
Upgrade
redhat/redhat-access-insights-puppetto a version that resolves this vulnerability.Fixed in 0:1.0.1-1.el7 - Upgrade
Upgrade
redhat/repoviewto a version that resolves this vulnerability.Fixed in 0:0.6.6-11.el7 - Upgrade
Upgrade
redhat/rhel8-kickstart-setupto a version that resolves this vulnerability.Fixed in 0:0.0.2-1.el7 - Upgrade
Upgrade
redhat/rh-postgresql12-postgresql-evrto a version that resolves this vulnerability.Fixed in 0:0.0.2-1.el7 - Upgrade
Upgrade
redhat/rubygem-facterto a version that resolves this vulnerability.Fixed in 0:2.4.1-2.el7 - Upgrade
Upgrade
redhat/rubygem-highlineto a version that resolves this vulnerability.Fixed in 0:1.7.8-3.el7 - Upgrade
Upgrade
redhat/rubygem-newtto a version that resolves this vulnerability.Fixed in 0:0.9.6-3.el7 - Upgrade
Upgrade
redhat/rubygem-oauthto a version that resolves this vulnerability.Fixed in 0:0.5.4-2.el7 - Upgrade
Upgrade
redhat/rubygem-passengerto a version that resolves this vulnerability.Fixed in 0:4.0.18-24.el7 - Upgrade
Upgrade
redhat/rubygem-rackto a version that resolves this vulnerability.Fixed in 1:1.6.12-1.el7 - Upgrade
Upgrade
redhat/rubygem-raketo a version that resolves this vulnerability.Fixed in 0:0.9.2.2-41.el7 - Upgrade
Upgrade
redhat/saslwrapperto a version that resolves this vulnerability.Fixed in 0:0.22-5.el7 - Upgrade
Upgrade
redhat/satelliteto a version that resolves this vulnerability.Fixed in 0:6.8.0-1.el7 - Upgrade
Upgrade
redhat/satellite-installerto a version that resolves this vulnerability.Fixed in 0:6.8.0.11-1.el7 - Upgrade
Upgrade
redhat/tfmto a version that resolves this vulnerability.Fixed in 0:6.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-actioncableto a version that resolves this vulnerability.Fixed in 0:6.0.3.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-actionmailboxto a version that resolves this vulnerability.Fixed in 0:6.0.3.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-actionmailerto a version that resolves this vulnerability.Fixed in 0:6.0.3.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-actionpackto a version that resolves this vulnerability.Fixed in 0:6.0.3.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-actiontextto a version that resolves this vulnerability.Fixed in 0:6.0.3.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-actionviewto a version that resolves this vulnerability.Fixed in 0:6.0.3.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-activejobto a version that resolves this vulnerability.Fixed in 0:6.0.3.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-activemodelto a version that resolves this vulnerability.Fixed in 0:6.0.3.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-activerecordto a version that resolves this vulnerability.Fixed in 0:6.0.3.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-activerecord-importto a version that resolves this vulnerability.Fixed in 0:1.0.0-6.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-activestorageto a version that resolves this vulnerability.Fixed in 0:6.0.3.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-activesupportto a version that resolves this vulnerability.Fixed in 0:6.0.3.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-addressableto a version that resolves this vulnerability.Fixed in 0:2.6.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-algebrickto a version that resolves this vulnerability.Fixed in 0:0.7.3-6.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-ancestryto a version that resolves this vulnerability.Fixed in 0:3.0.7-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-anemoneto a version that resolves this vulnerability.Fixed in 0:0.7.2-22.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-angular-rails-templatesto a version that resolves this vulnerability.Fixed in 1:1.1.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-ansito a version that resolves this vulnerability.Fixed in 0:1.5.0-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-apipie-bindingsto a version that resolves this vulnerability.Fixed in 0:0.3.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-apipie-dslto a version that resolves this vulnerability.Fixed in 0:2.2.2-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-apipie-paramsto a version that resolves this vulnerability.Fixed in 0:0.0.5-5.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-apipie-railsto a version that resolves this vulnerability.Fixed in 0:0.5.17-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-auditedto a version that resolves this vulnerability.Fixed in 0:4.9.0-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-bcryptto a version that resolves this vulnerability.Fixed in 0:3.1.12-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-builderto a version that resolves this vulnerability.Fixed in 0:3.2.4-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-clampto a version that resolves this vulnerability.Fixed in 0:1.1.2-5.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-coffee-railsto a version that resolves this vulnerability.Fixed in 0:5.0.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-coffee-scriptto a version that resolves this vulnerability.Fixed in 0:2.4.1-4.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-coffee-script-sourceto a version that resolves this vulnerability.Fixed in 0:1.12.2-4.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-concurrent-rubyto a version that resolves this vulnerability.Fixed in 1:1.1.6-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-concurrent-ruby-edgeto a version that resolves this vulnerability.Fixed in 1:0.6.0-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-crassto a version that resolves this vulnerability.Fixed in 0:1.0.6-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-daemonsto a version that resolves this vulnerability.Fixed in 0:1.2.3-7.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-deaconto a version that resolves this vulnerability.Fixed in 0:1.0.0-4.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-declarativeto a version that resolves this vulnerability.Fixed in 0:0.0.10-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-declarative-optionto a version that resolves this vulnerability.Fixed in 0:0.1.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-defaceto a version that resolves this vulnerability.Fixed in 0:1.5.3-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-diffyto a version that resolves this vulnerability.Fixed in 0:3.0.1-6.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-dynflowto a version that resolves this vulnerability.Fixed in 0:1.4.7-1.fm2_1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-erubito a version that resolves this vulnerability.Fixed in 0:1.9.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-exconto a version that resolves this vulnerability.Fixed in 0:0.58.0-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-execjsto a version that resolves this vulnerability.Fixed in 0:2.7.0-4.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-facterto a version that resolves this vulnerability.Fixed in 0:2.4.0-6.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-faradayto a version that resolves this vulnerability.Fixed in 0:0.15.4-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-ffito a version that resolves this vulnerability.Fixed in 0:1.12.2-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-fog-awsto a version that resolves this vulnerability.Fixed in 0:3.6.5-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-fog-coreto a version that resolves this vulnerability.Fixed in 0:2.1.0-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-fog-googleto a version that resolves this vulnerability.Fixed in 0:1.8.2-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-fog-jsonto a version that resolves this vulnerability.Fixed in 0:1.2.0-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-fog-kubevirtto a version that resolves this vulnerability.Fixed in 0:1.3.3-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-fog-libvirtto a version that resolves this vulnerability.Fixed in 0:0.7.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-fog-openstackto a version that resolves this vulnerability.Fixed in 0:1.0.8-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-fog-ovirtto a version that resolves this vulnerability.Fixed in 0:1.2.5-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-fog-vsphereto a version that resolves this vulnerability.Fixed in 0:3.3.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-fog-xmlto a version that resolves this vulnerability.Fixed in 0:0.1.2-8.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-foreman-tasksto a version that resolves this vulnerability.Fixed in 0:2.0.2-1.fm2_1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-foreman-tasks-coreto a version that resolves this vulnerability.Fixed in 0:0.3.4-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-formatadorto a version that resolves this vulnerability.Fixed in 0:0.2.1-11.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-fxto a version that resolves this vulnerability.Fixed in 0:0.5.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-gettextto a version that resolves this vulnerability.Fixed in 0:3.1.4-10.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-gitto a version that resolves this vulnerability.Fixed in 0:1.5.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-gitlab-sidekiq-fetcherto a version that resolves this vulnerability.Fixed in 0:0.5.2-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-globalidto a version that resolves this vulnerability.Fixed in 0:0.4.2-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-google-api-clientto a version that resolves this vulnerability.Fixed in 0:0.23.9-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-googleauthto a version that resolves this vulnerability.Fixed in 0:0.6.7-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-graphqlto a version that resolves this vulnerability.Fixed in 0:1.8.14-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-graphql-batchto a version that resolves this vulnerability.Fixed in 0:0.3.10-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-gssapito a version that resolves this vulnerability.Fixed in 0:1.2.0-6.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-hashieto a version that resolves this vulnerability.Fixed in 0:3.6.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-highlineto a version that resolves this vulnerability.Fixed in 0:1.7.8-4.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-httpto a version that resolves this vulnerability.Fixed in 0:3.3.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-httpclientto a version that resolves this vulnerability.Fixed in 0:2.8.3-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-http-cookieto a version that resolves this vulnerability.Fixed in 0:1.0.2-5.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-i18nto a version that resolves this vulnerability.Fixed in 0:1.8.2-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-infobloxto a version that resolves this vulnerability.Fixed in 0:3.0.0-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-ipaddressto a version that resolves this vulnerability.Fixed in 0:0.8.0-11.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-jgrepto a version that resolves this vulnerability.Fixed in 0:1.3.3-12.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-journald-loggerto a version that resolves this vulnerability.Fixed in 0:2.0.4-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-journald-nativeto a version that resolves this vulnerability.Fixed in 0:1.0.11-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-jwtto a version that resolves this vulnerability.Fixed in 0:2.2.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-kafoto a version that resolves this vulnerability.Fixed in 0:4.1.0-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-katelloto a version that resolves this vulnerability.Fixed in 0:3.16.0.11-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-kubeclientto a version that resolves this vulnerability.Fixed in 0:4.3.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-little-pluggerto a version that resolves this vulnerability.Fixed in 0:1.1.4-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-localeto a version that resolves this vulnerability.Fixed in 0:2.0.9-13.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-loggingto a version that resolves this vulnerability.Fixed in 0:2.2.2-6.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-logging-journaldto a version that resolves this vulnerability.Fixed in 0:2.0.0-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-loofahto a version that resolves this vulnerability.Fixed in 0:2.4.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-mailto a version that resolves this vulnerability.Fixed in 0:2.7.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-marcelto a version that resolves this vulnerability.Fixed in 0:0.3.3-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-memoistto a version that resolves this vulnerability.Fixed in 0:0.16.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-mimemagicto a version that resolves this vulnerability.Fixed in 0:0.3.5-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-mime-typesto a version that resolves this vulnerability.Fixed in 0:3.2.2-4.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-mime-types-datato a version that resolves this vulnerability.Fixed in 0:3.2018.0812-4.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-multipart-postto a version that resolves this vulnerability.Fixed in 0:2.0.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-mustermannto a version that resolves this vulnerability.Fixed in 0:1.0.2-4.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-net-ldapto a version that resolves this vulnerability.Fixed in 0:0.16.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-net-pingto a version that resolves this vulnerability.Fixed in 0:2.0.1-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-netrcto a version that resolves this vulnerability.Fixed in 0:0.11.0-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-net-scpto a version that resolves this vulnerability.Fixed in 0:1.2.1-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-net-sshto a version that resolves this vulnerability.Fixed in 0:4.2.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-net-ssh-krbto a version that resolves this vulnerability.Fixed in 0:0.4.0-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-nio4rto a version that resolves this vulnerability.Fixed in 0:2.5.2-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-nokogirito a version that resolves this vulnerability.Fixed in 0:1.10.9-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-oauthto a version that resolves this vulnerability.Fixed in 0:0.5.4-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-openscapto a version that resolves this vulnerability.Fixed in 0:0.4.9-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-optimistto a version that resolves this vulnerability.Fixed in 0:3.0.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-osto a version that resolves this vulnerability.Fixed in 0:1.0.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-ovirt-engine-sdkto a version that resolves this vulnerability.Fixed in 0:4.2.3-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-parse-cronto a version that resolves this vulnerability.Fixed in 0:0.1.4-4.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-passengerto a version that resolves this vulnerability.Fixed in 0:4.0.18-26.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-pgto a version that resolves this vulnerability.Fixed in 0:1.1.4-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-polyglotto a version that resolves this vulnerability.Fixed in 0:0.3.5-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-powerbarto a version that resolves this vulnerability.Fixed in 0:2.0.1-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-prometheus-clientto a version that resolves this vulnerability.Fixed in 0:1.0.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-promise.rbto a version that resolves this vulnerability.Fixed in 0:0.7.4-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-pumato a version that resolves this vulnerability.Fixed in 0:4.3.3-4.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-puma-plugin-systemdto a version that resolves this vulnerability.Fixed in 0:0.1.5-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-quantileto a version that resolves this vulnerability.Fixed in 0:0.2.0-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-rablto a version that resolves this vulnerability.Fixed in 0:0.14.3-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-rackto a version that resolves this vulnerability.Fixed in 0:2.2.3-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-rack-corsto a version that resolves this vulnerability.Fixed in 0:1.0.2-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-rack-jsonpto a version that resolves this vulnerability.Fixed in 0:1.3.1-9.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-rack-protectionto a version that resolves this vulnerability.Fixed in 0:2.0.3-4.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-rack-testto a version that resolves this vulnerability.Fixed in 0:1.1.0-4.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-railsto a version that resolves this vulnerability.Fixed in 0:6.0.3.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-rails-dom-testingto a version that resolves this vulnerability.Fixed in 0:2.0.3-6.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-rails-html-sanitizerto a version that resolves this vulnerability.Fixed in 0:1.3.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-rails-i18nto a version that resolves this vulnerability.Fixed in 0:6.0.0-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-railtiesto a version that resolves this vulnerability.Fixed in 0:6.0.3.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-rainbowto a version that resolves this vulnerability.Fixed in 0:2.2.1-5.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-rb-inotifyto a version that resolves this vulnerability.Fixed in 0:0.9.7-5.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-rbovirtto a version that resolves this vulnerability.Fixed in 0:0.1.7-4.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-rbvmomito a version that resolves this vulnerability.Fixed in 0:2.2.0-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-recursive-open-structto a version that resolves this vulnerability.Fixed in 0:1.1.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-redisto a version that resolves this vulnerability.Fixed in 0:4.1.2-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-representableto a version that resolves this vulnerability.Fixed in 0:3.0.4-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-respondersto a version that resolves this vulnerability.Fixed in 0:3.0.0-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-rest-clientto a version that resolves this vulnerability.Fixed in 0:2.0.2-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-retriableto a version that resolves this vulnerability.Fixed in 0:3.1.2-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-rkerberosto a version that resolves this vulnerability.Fixed in 0:0.1.5-18.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-roadieto a version that resolves this vulnerability.Fixed in 0:3.4.0-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-roadie-railsto a version that resolves this vulnerability.Fixed in 0:2.1.1-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-robotexto a version that resolves this vulnerability.Fixed in 0:1.0.0-21.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-rsecto a version that resolves this vulnerability.Fixed in 0:0.4.3-4.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-ruby2rubyto a version that resolves this vulnerability.Fixed in 0:2.4.2-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-rubyipmito a version that resolves this vulnerability.Fixed in 0:0.10.0-6.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-ruby-libvirtto a version that resolves this vulnerability.Fixed in 0:0.7.0-4.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-runcibleto a version that resolves this vulnerability.Fixed in 0:2.13.0-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-safemodeto a version that resolves this vulnerability.Fixed in 0:1.3.5-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-sequelto a version that resolves this vulnerability.Fixed in 0:5.7.1-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-sidekiqto a version that resolves this vulnerability.Fixed in 0:5.2.7-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-signetto a version that resolves this vulnerability.Fixed in 0:0.11.0-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-sinatrato a version that resolves this vulnerability.Fixed in 0:2.0.3-4.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-sprocketsto a version that resolves this vulnerability.Fixed in 0:3.7.2-6.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-sprockets-railsto a version that resolves this vulnerability.Fixed in 0:3.2.1-6.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-sqlite3to a version that resolves this vulnerability.Fixed in 0:1.3.13-5.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-sshkeyto a version that resolves this vulnerability.Fixed in 0:1.9.0-3.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-statsd-instrumentto a version that resolves this vulnerability.Fixed in 0:2.1.4-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-stompto a version that resolves this vulnerability.Fixed in 0:1.4.9-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-textto a version that resolves this vulnerability.Fixed in 0:1.3.0-7.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-thorto a version that resolves this vulnerability.Fixed in 0:1.0.1-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-tiltto a version that resolves this vulnerability.Fixed in 0:2.0.8-4.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-timelinessto a version that resolves this vulnerability.Fixed in 0:0.3.10-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-tzinfoto a version that resolves this vulnerability.Fixed in 0:1.2.6-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-uberto a version that resolves this vulnerability.Fixed in 0:0.1.0-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-unfto a version that resolves this vulnerability.Fixed in 0:0.1.3-7.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-unicodeto a version that resolves this vulnerability.Fixed in 0:0.4.4.4-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-webpack-railsto a version that resolves this vulnerability.Fixed in 0:0.9.8-6.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-websocket-driverto a version that resolves this vulnerability.Fixed in 0:0.7.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-websocket-extensionsto a version that resolves this vulnerability.Fixed in 0:0.1.5-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-x-editable-railsto a version that resolves this vulnerability.Fixed in 0:1.5.5-5.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-xmlrpcto a version that resolves this vulnerability.Fixed in 0:0.3.0-2.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-zeitwerkto a version that resolves this vulnerability.Fixed in 0:2.2.2-1.el7 - Upgrade
Upgrade
RubyGem secure_headersto a version that resolves this vulnerability.Fixed in 6.3.0Patch GHSA-w978-rmpf-qmwg - Upgrade
Upgrade
RubyGem secure_headersto a version that resolves this vulnerability.Fixed in 5.2.0Patch GHSA-w978-rmpf-qmwg - Upgrade
Upgrade
RubyGem secure_headersto a version that resolves this vulnerability.Fixed in 3.9.0Patch GHSA-w978-rmpf-qmwg
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5216?
CVE-2020-5216 has a medium severity level due to its potential for limited header injection.
How do I fix CVE-2020-5216?
To fix CVE-2020-5216, update to versions 3.9.0, 5.2.0, or 6.3.0 of the Secure Headers RubyGem.
What types of inputs are vulnerable in CVE-2020-5216?
CVE-2020-5216 is vulnerable to user-supplied input being passed into certain functions.
Which software is affected by CVE-2020-5216?
CVE-2020-5216 affects multiple packages including Twitter Secure Headers versions lower than 3.9.0, between 5.0.0 and 5.2.0, and between 6.0.0 and 6.3.0.
What impacts does CVE-2020-5216 have on applications?
CVE-2020-5216 may lead to limited header injections that could potentially compromise content security policies.