PT-2016-3800 · Phusion+1 · Phusion Passenger+1
Adrian Schröter
·
Published
2015-12-21
·
Updated
2018-10-10
·
CVE-2015-7519
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Phusion Passenger versions prior to 4.0.60
Phusion Passenger versions 5.0.x prior to 5.0.22
Description
The issue allows remote attackers to spoof headers passed to applications by using an (underscore) character instead of a - (dash) character in an HTTP header. This can be demonstrated by an X User header. The problem occurs when Phusion Passenger is used in Apache integration mode or in standalone mode without a filtering proxy.
Recommendations
For Phusion Passenger versions prior to 4.0.60, update to version 4.0.60 or later.
For Phusion Passenger versions 5.0.x prior to 5.0.22, update to version 5.0.22 or later.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phusion Passenger
Suse