rubygem-rack: Cross-site scripting (XSS) via `scheme` method on `Rack::Request`
Published Nov 13, 2018
6.1
MEDIUMCVSS 3.0
EPSS 1.89%
Description
There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value could be vulnerable to an XSS attack. Note that applications using the normal escaping mechanisms provided by Rails may not impacted, but applications that bypass the escaping mechanisms, or do not use them may be vulnerable.
Affected products
-
- Version 2.0.6, 1.6.11StatusaffectedConstraints-
- Version
Configuration 1
- ≥ 1.6.0 · < 1.6.11
- ≥ 2.0.0 · < 2.0.6
Configuration 2
- 8.0
No data.
CloudForms Management Engine 5
cfme-amazon-smartstate
Not affected
CloudForms Management Engine 5
cfme-gemset
Not affected
CloudForms Management Engine 5
dpus-api-service
Not affected
Red Hat OpenShift Container Platform 3.2
rubygem-rack
Not affected
Red Hat OpenShift Container Platform 3.3
rubygem-rack
Not affected
Red Hat OpenShift Container Platform 3.4
rubygem-rack
Not affected
Red Hat OpenShift Enterprise 3.1
rubygem-rack
Not affected
Red Hat OpenStack Platform 10 (Newton) Operational Tools
rubygem-rack
Not affected
Red Hat OpenStack Platform 12 (Pike) Operational Tools
rubygem-rack
Not affected
Red Hat OpenStack Platform 13 (Queens) Operational Tools
rubygem-rack
Not affected
Red Hat OpenStack Platform 14 (Rocky) Operational Tools
rubygem-rack
Not affected
Red Hat OpenStack Platform 8 (Liberty) Operational Tools
rubygem-rack
Not affected
Red Hat OpenStack Platform 9 (Mitaka) Operational Tools
rubygem-rack
Not affected
Red Hat Satellite 6
rubygem-rack
Not affected
Red Hat Satellite 6
tfm-ror51-rubygem-rack
Not affected
Red Hat Software Collections
rh-ror42-rubygem-rack
Will not fix
Red Hat Software Collections
rh-ror50-rubygem-rack
Will not fix
Red Hat Storage 3
rubygem-rack
Will not fix
Red Hat Subscription Asset Manager
ruby193-rubygem-rack
Will not fix
Red Hat Update Infrastructure 3 for Cloud Providers
rubygem-rack
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5 | cfme-amazon-smartstate | Not affected | n/a |
| CloudForms Management Engine 5 | cfme-gemset | Not affected | n/a |
| CloudForms Management Engine 5 | dpus-api-service | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.2 | rubygem-rack | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.3 | rubygem-rack | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.4 | rubygem-rack | Not affected | n/a |
| Red Hat OpenShift Enterprise 3.1 | rubygem-rack | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) Operational Tools | rubygem-rack | Not affected | n/a |
| Red Hat OpenStack Platform 12 (Pike) Operational Tools | rubygem-rack | Not affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) Operational Tools | rubygem-rack | Not affected | n/a |
| Red Hat OpenStack Platform 14 (Rocky) Operational Tools | rubygem-rack | Not affected | n/a |
| Red Hat OpenStack Platform 8 (Liberty) Operational Tools | rubygem-rack | Not affected | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) Operational Tools | rubygem-rack | Not affected | n/a |
| Red Hat Satellite 6 | rubygem-rack | Not affected | n/a |
| Red Hat Satellite 6 | tfm-ror51-rubygem-rack | Not affected | n/a |
| Red Hat Software Collections | rh-ror42-rubygem-rack | Will not fix | n/a |
| Red Hat Software Collections | rh-ror50-rubygem-rack | Will not fix | n/a |
| Red Hat Storage 3 | rubygem-rack | Will not fix | n/a |
| Red Hat Subscription Asset Manager | ruby193-rubygem-rack | Will not fix | n/a |
| Red Hat Update Infrastructure 3 for Cloud Providers | rubygem-rack | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat OpenStack Platform and OpenShift Enterprise are not affected. Whilst the version of rack in use as a dependency in optional components is vulnerable, the vulnerable variable is not used in a way that could lead to XSS. Subscription Asset Manager is now in a reduced support phase receiving only Critical impact security fixes. This issue has been rated as having a security impact Moderate, and is not currently planned to be addressed in future updates. Red Hat CloudForms and Satellite 6 are not affected. Whilst the version of rack in use as a dependency in optional components is vulnerable, the vulnerable variable is not used in a way that could lead to XSS.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2021-2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (14 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 1.89% (0.01890) | 78.84th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.82% (0.01816) | 75.81th | v5 (v2026.06.15) |
| Aug 8, 2025 | 0.18% (0.00178) | 39.78th | v4 (v2025.03.14) |
| Jul 20, 2024 | 0.80% (0.00798) | 81.82th | v3 (v2023.03.01) |
| Jul 2, 2024 | 0.80% (0.00798) | 81.73th | v3 (v2023.03.01) |
| Mar 14, 2024 | 0.59% (0.00587) | 77.73th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.59% (0.00587) | 75.72th | v3 (v2023.03.01) |
| Nov 7, 2023 | 0.46% (0.00464) | 72.76th | v3 (v2023.03.01) |
| Jul 8, 2023 | 0.73% (0.00734) | 78.26th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.76% (0.01756) | 86.00th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.02% (0.01018) | 40.69th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.02% (0.01018) | 19.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.25% (0.01247) | 30.57th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.25% (0.01247) | 0.00th | v1 |
References (14)
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00032.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00016.html vendor-advisoryx_refsource_SUSE
- https://access.redhat.com/security/cve/CVE-2018-16471 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1646818 Issue Tracking
- https://github.com/advisories/GHSA-5r2p-j47h-mhpg Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rack/CVE-2018-16471.yml
- https://groups.google.com/d/msg/rubyonrails-security/GKsAFT924Ag/DYtk-Xl6AAAJ
- https://groups.google.com/forum/#!topic/ruby-security-ann/NAalCee8n6o
- https://groups.google.com/forum/#!topic/rubyonrails-security/GKsAFT924Ag
- https://groups.google.com/forum/#%21topic/rubyonrails-security/GKsAFT924Ag x_refsource_MISC
- https://lists.debian.org/debian-lts-announce/2018/11/msg00022.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-16471
- https://usn.ubuntu.com/4089-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2018-16471
Change history (0)
No recorded changes yet.