PT-2016-3800 · Phusion+1 · Phusion Passenger+1
Adrian Schröter
·
Publicado
2015-12-21
·
Atualizado
2018-10-10
·
CVE-2015-7519
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Phusion Passenger versions prior to 4.0.60
Phusion Passenger versions 5.0.x prior to 5.0.22
Description
The issue allows remote attackers to spoof headers passed to applications by using an (underscore) character instead of a - (dash) character in an HTTP header. This can be demonstrated by an X User header. The problem occurs when Phusion Passenger is used in Apache integration mode or in standalone mode without a filtering proxy.
Recommendations
For Phusion Passenger versions prior to 4.0.60, update to version 4.0.60 or later.
For Phusion Passenger versions 5.0.x prior to 5.0.22, update to version 5.0.22 or later.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Phusion Passenger
Suse