ruby: HTTP response splitting in WEBrick
Published Nov 26, 2019
5.3
MEDIUMCVSS 3.1
EPSS 4.57%
Description
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input into the response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. NOTE: this issue exists because of an incomplete fix for CVE-2017-17742, which addressed the CRLF vector, but did not address an isolated CR or an isolated LF.
Affected products
No data.
No data.
Red Hat Enterprise Linux 8
ruby:2.5-8040020200923213910.522a0ee4
Fixed · RHSA-2021:2587
Red Hat Enterprise Linux 8
ruby:2.6-8040020210430142949.522a0ee4
Fixed · RHSA-2021:2588
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
ruby:2.6-8010020220201152941.c27ad7f8
Fixed · RHSA-2022:0581
Red Hat Enterprise Linux 8.2 Extended Update Support
ruby:2.6-8020020220201131207.4cda2c84
Fixed · RHSA-2022:0582
Red Hat Hardened Images
ruby3-3-main-3.3.10-23.1.hum1
Fixed · RHSA-2026:7305
Red Hat Hardened Images
ruby3-4-main-3.4.8-31.1.hum1
Fixed · RHSA-2026:7307
Red Hat Hardened Images
ruby4-0-main-4.0.0-33.3.hum1
Fixed · RHSA-2026:8838
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-ruby25-ruby-0:2.5.9-9.el7
Fixed · RHSA-2021:2104
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-ruby26-ruby-0:2.6.7-119.el7
Fixed · RHSA-2021:2230
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-ruby25-ruby-0:2.5.9-9.el7
Fixed · RHSA-2021:2104
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-ruby25-ruby-0:2.5.9-9.el7
Fixed · RHSA-2021:2104
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-ruby26-ruby-0:2.6.7-119.el7
Fixed · RHSA-2021:2230
Red Hat 3scale API Management Platform 2
3amp-system
Fix deferred
Red Hat Enterprise Linux 5
ruby
Out of support scope
Red Hat Enterprise Linux 6
ruby
Out of support scope
Red Hat Enterprise Linux 7
ruby
Fix deferred
Red Hat Software Collections
rh-ruby24-ruby
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | ruby:2.5-8040020200923213910.522a0ee4 | Fixed | RHSA-2021:2587 |
| Red Hat Enterprise Linux 8 | ruby:2.6-8040020210430142949.522a0ee4 | Fixed | RHSA-2021:2588 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | ruby:2.6-8010020220201152941.c27ad7f8 | Fixed | RHSA-2022:0581 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | ruby:2.6-8020020220201131207.4cda2c84 | Fixed | RHSA-2022:0582 |
| Red Hat Hardened Images | ruby3-3-main-3.3.10-23.1.hum1 | Fixed | RHSA-2026:7305 |
| Red Hat Hardened Images | ruby3-4-main-3.4.8-31.1.hum1 | Fixed | RHSA-2026:7307 |
| Red Hat Hardened Images | ruby4-0-main-4.0.0-33.3.hum1 | Fixed | RHSA-2026:8838 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-ruby25-ruby-0:2.5.9-9.el7 | Fixed | RHSA-2021:2104 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-ruby26-ruby-0:2.6.7-119.el7 | Fixed | RHSA-2021:2230 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-ruby25-ruby-0:2.5.9-9.el7 | Fixed | RHSA-2021:2104 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-ruby25-ruby-0:2.5.9-9.el7 | Fixed | RHSA-2021:2104 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-ruby26-ruby-0:2.6.7-119.el7 | Fixed | RHSA-2021:2230 |
| Red Hat 3scale API Management Platform 2 | 3amp-system | Fix deferred | n/a |
| Red Hat Enterprise Linux 5 | ruby | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | ruby | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | ruby | Fix deferred | n/a |
| Red Hat Software Collections | rh-ruby24-ruby | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (20)
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.html vendor-advisory
- https://access.redhat.com/security/cve/CVE-2019-16254 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1789556 Issue Tracking
- https://hackerone.com/reports/331984 Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/11/msg00025.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/12/msg00009.html mailing-list
- https://lists.debian.org/debian-lts-announce/2020/08/msg00027.html mailing-list
- https://lists.debian.org/debian-lts-announce/2023/04/msg00033.html mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2019-16254
- https://seclists.org/bugtraq/2019/Dec/31 mailing-list
- https://seclists.org/bugtraq/2019/Dec/32 mailing-list
- https://security.gentoo.org/glsa/202003-06 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-16254
- https://www.debian.org/security/2019/dsa-4586 vendor-advisory
- https://www.debian.org/security/2019/dsa-4587 vendor-advisory
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.ruby-lang.org/ja/news/2019/10/01/http-response-splitting-in-webrick-cve-2019-16254/ Vendor Advisory
- https://www.ruby-lang.org/ja/news/2019/10/01/ruby-2-4-8-released/ Vendor Advisory
- https://www.ruby-lang.org/ja/news/2019/10/01/ruby-2-5-7-released/ Vendor Advisory
- https://www.ruby-lang.org/ja/news/2019/10/01/ruby-2-6-5-released/ Vendor Advisory
Change history (0)
No recorded changes yet.