CVE-2011-3186
29.08.2011, 18:55
CRLF injection vulnerability in actionpack/lib/action_controller/response.rb in Ruby on Rails 2.3.x before 2.3.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the Content-Type header.
Vendor | Product | Version |
---|---|---|
rubyonrails | rails | 2.3.2 |
rubyonrails | rails | 2.3.3 |
rubyonrails | rails | 2.3.4 |
rubyonrails | rails | 2.3.9 |
rubyonrails | rails | 2.3.10 |
rubyonrails | rails | 2.3.11 |
rubyonrails | rails | 2.3.12 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References