An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., GET /admin HTTP/1.1rn inside of a POST /user HTTP/1.1rn request. NOTE: the suppliers position is Webrick should not be used in production.
Name | Vendor | Start Version | End Version |
---|---|---|---|
RHOL-5.9-RHEL-9 | RedHat | openshift-logging/cluster-logging-operator-bundle:v5.9.11-25 | * |
RHOL-5.9-RHEL-9 | RedHat | openshift-logging/cluster-logging-rhel9-operator:v5.9.11-11 | * |
RHOL-5.9-RHEL-9 | RedHat | openshift-logging/eventrouter-rhel9:v0.4.0-340 | * |
RHOL-5.9-RHEL-9 | RedHat | openshift-logging/fluentd-rhel9:v5.9.11-5 | * |
RHOL-5.9-RHEL-9 | RedHat | openshift-logging/log-file-metric-exporter-rhel9:v1.1.0-321 | * |
RHOL-5.9-RHEL-9 | RedHat | openshift-logging/logging-loki-rhel9:v3.3.2-8 | * |
RHOL-5.9-RHEL-9 | RedHat | openshift-logging/logging-view-plugin-rhel9:v5.9.11-6 | * |
RHOL-5.9-RHEL-9 | RedHat | openshift-logging/loki-operator-bundle:v5.9.11-9 | * |
RHOL-5.9-RHEL-9 | RedHat | openshift-logging/loki-rhel9-operator:v5.9.11-4 | * |
RHOL-5.9-RHEL-9 | RedHat | openshift-logging/lokistack-gateway-rhel9:v0.1.0-724 | * |
RHOL-5.9-RHEL-9 | RedHat | openshift-logging/opa-openshift-rhel9:v0.1.0-341 | * |
RHOL-5.9-RHEL-9 | RedHat | openshift-logging/vector-rhel9:v0.34.1-30 | * |
Ruby-webrick | Ubuntu | devel | * |
Ruby-webrick | Ubuntu | esm-apps/jammy | * |
Ruby-webrick | Ubuntu | jammy | * |
Ruby-webrick | Ubuntu | noble | * |
Ruby-webrick | Ubuntu | oracular | * |