PT-2016-3800 · Phusion+1 · Phusion Passenger+1

Adrian Schröter

·

Published

2015-12-21

·

Updated

2018-10-10

·

CVE-2015-7519

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Phusion Passenger versions prior to 4.0.60 Phusion Passenger versions 5.0.x prior to 5.0.22
Description The issue allows remote attackers to spoof headers passed to applications by using an (underscore) character instead of a - (dash) character in an HTTP header. This can be demonstrated by an X User header. The problem occurs when Phusion Passenger is used in Apache integration mode or in standalone mode without a filtering proxy.
Recommendations For Phusion Passenger versions prior to 4.0.60, update to version 4.0.60 or later. For Phusion Passenger versions 5.0.x prior to 5.0.22, update to version 5.0.22 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-7519
DLA-1399-1
DLA-394-1
GHSA-FXWV-953P-7QPF
OPENSUSE-SU-2024:11341-1
SUSE-SU-2015:2337-1
SUSE-SU-2015_2337-1
SUSE-SU-2016:0042-1

Affected Products

Phusion Passenger
Suse