CVE-2025-25184

EUVD-2025-4075
Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.11, 3.0.12, and 3.1.10, Rack::CommonLogger can be exploited by crafting input that includes newline characters to manipulate log entries. The supplied proof-of-concept demonstrates injecting malicious content into logs. When a user provides the authorization credentials via Rack::Auth::Basic, if success, the username will be put in env['REMOTE_USER'] and later be used by Rack::CommonLogger for logging purposes. The issue occurs when a server intentionally or unintentionally allows a user creation with the username contain CRLF and white space characters, or the server just want to log every login attempts. If an attacker enters a username with CRLF character, the logger will log the malicious username with CRLF characters into the logfile. Attackers can break log formats or insert fraudulent entries, potentially obscuring real activity or injecting malicious data into log files. Versions 2.2.11, 3.0.12, and 3.1.10 contain a fix.
CRLF Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 65.05%
Affected Products (NVD)
VendorProductVersion
rackrack
𝑥
< 2.2.11
rackrack
3.0.0 ≤
𝑥
< 3.0.12
rackrack
3.1.0 ≤
𝑥
< 3.1.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ruby-rack
bookworm
2.2.22-0+deb12u1
fixed
bookworm (security)
2.2.22-0+deb12u2
fixed
bullseye
vulnerable
bullseye (security)
2.1.4-3+deb11u6
fixed
forky
3.2.6-3
fixed
sid
3.2.6-3
fixed
trixie
3.1.20-0+deb13u1
fixed
trixie (security)
3.1.20-0+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ruby-rack
bionic
Fixed 1.6.4-4ubuntu0.2+esm7
released
focal
Fixed 2.0.7-2ubuntu0.1+esm6
released
jammy
Fixed 2.1.4-5ubuntu1.1+esm1
released
noble
Fixed 2.2.7-1ubuntu0.2
released
oracular
Fixed 2.2.7-1.1ubuntu0.1
released
plucky
Fixed 2.2.7-1.1ubuntu0.25.04.2
released
questing
Fixed 3.1.16-0.1
released
resolute
Fixed 3.1.16-0.1
released
trusty
Fixed 1.5.2-3+deb8u3ubuntu1~esm9
released
xenial
Fixed 1.6.4-3ubuntu0.2+esm7
released
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
pcs
RHEL 9
0:0.11.9-2.el9
fixed
pcs-snmp
RHEL 9
0:0.11.9-2.el9
fixed