Wind River Support Network

HomeDefectsLIN1018-6760
Fixed

LIN1018-6760 : Security Advisory - ruby - CVE-2020-25613

Created: Oct 11, 2020    Updated: Mar 23, 2021
Resolved Date: Mar 23, 2021
Found In Version: 10.18.44.1
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issue to bypass a reverse proxy (which also has a poor header check), which may lead to an HTTP Request Smuggling attack.

CREATE(Triage):(User=admin) [CVE-2020-25613|https://nvd.nist.gov/vuln/detail/CVE-2020-25613]

CVEs


Live chat
Online