PT-2021-7376 · Ruby+11 · Ruby+11

Oooooo_Q

·

Published

2021-11-24

·

Updated

2025-12-12

·

CVE-2021-41819

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Ruby versions through 2.6.8 CGI gem versions through 0.3.0
Description The issue is related to the CGI::Cookie.parse function in Ruby, which mishandles security prefixes in cookie names. This allows a remote attacker to impact data integrity. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations For Ruby versions through 2.6.8, update to a version later than 2.6.8 to resolve the issue. For CGI gem versions through 0.3.0, update to a version later than 0.3.0 to resolve the issue. As a temporary workaround, consider restricting the use of the CGI::Cookie.parse function until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:0543
ALSA-2022:5779
ALSA-2022:6447
ALSA-2022:6450
ALSA-2022_5779
ALSA-2022_6447
ALSA-2022_6450
ALSA-2025_16880
ALT-PU-2021-3482
ALT-PU-2022-2699
ALT-PU-2023-4264
ALT-PU-2024-7811
AZL-7126
BDU:2022-05837
BIT-RUBY-2021-41819
BIT-RUBY-MIN-2021-41819
CESA-2022_0543
CESA-2022_5779
CESA-2022_6447
CESA-2022_6450
CVE-2021-41819
DLA-2853-1
DSA-5066-1
DSA-5067-1
ELSA-2022-0543
ELSA-2022-5779
ELSA-2022-6447
ELSA-2022-6450
GHSA-4VF4-QMVG-MH7H
MGASA-2021-0579
OESA-2022-1497
OPENSUSE-SU-2022_3292-1
OPENSUSE-SU-2024:11657-1
OPENSUSE-SU-2024:11658-1
OPENSUSE-SU-2024:11786-1
OPENSUSE-SU-2024:12712-1
OPENSUSE-SU-2024:13623-1
OPENSUSE-SU-2025:14621-1
OPENSUSE-SU-2025:15819-1
RHSA-2022:0543
RHSA-2022:0544
RHSA-2022:0581
RHSA-2022:0582
RHSA-2022:0708
RHSA-2022:5779
RHSA-2022:6447
RHSA-2022:6450
RHSA-2022:6855
RHSA-2022:6856
RHSA-2022_0543
RHSA-2022_5779
RHSA-2022_6447
RHSA-2022_6450
RHSA-2026:7305
RHSA-2026:7307
RHSA-2026:8838
RLSA-2022:0543
RLSA-2022:5779
RLSA-2022:6447
RLSA-2022:6450
RLSA-2022_0543
RLSA-2022_5779
RLSA-2022_6447
RLSA-2022_6450
SUSE-SU-2022:3292-1
SUSE-SU-2022_3292-1
USN-5235-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Cgi Gem
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Ruby
Suse
Ubuntu