CVE-2017-17742
Public on 2018-04-03
Modified on 2019-08-27
Description
It was found that WEBrick did not sanitize headers sent back to clients, resulting in a response-splitting vulnerability. An attacker, able to control the server's headers, could force WEBrick into injecting additional headers to a client.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | ruby | 2019-08-23 | ALAS2-2019-1276 | Fixed |
| Amazon Linux 1 | ruby20 | 2018-04-04 | ALAS-2018-983 | Fixed |
| Amazon Linux 1 | ruby22 | 2018-04-04 | ALAS-2018-983 | Fixed |
| Amazon Linux 1 | ruby23 | 2018-04-04 | ALAS-2018-983 | Fixed |
| Amazon Linux 1 | ruby24 | 2018-04-04 | ALAS-2018-983 | Fixed |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 4.7 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N |