PT-2016-3800 · Phusion+1 · Phusion Passenger+1

Adrian Schröter

·

Publicado

2015-12-21

·

Atualizado

2018-10-10

·

CVE-2015-7519

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Phusion Passenger versions prior to 4.0.60 Phusion Passenger versions 5.0.x prior to 5.0.22
Description The issue allows remote attackers to spoof headers passed to applications by using an (underscore) character instead of a - (dash) character in an HTTP header. This can be demonstrated by an X User header. The problem occurs when Phusion Passenger is used in Apache integration mode or in standalone mode without a filtering proxy.
Recommendations For Phusion Passenger versions prior to 4.0.60, update to version 4.0.60 or later. For Phusion Passenger versions 5.0.x prior to 5.0.22, update to version 5.0.22 or later.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-7519
DLA-1399-1
DLA-394-1
GHSA-FXWV-953P-7QPF
OPENSUSE-SU-2024:11341-1
SUSE-SU-2015:2337-1
SUSE-SU-2015_2337-1
SUSE-SU-2016:0042-1

Produtos afetados

Phusion Passenger
Suse