Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-33621


The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.


Published

2022-11-18T23:15:18.987

Last Modified

2024-11-21T06:09:12.553

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-74

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ruby-lang cgi < 0.1.0.2 Yes
Application ruby-lang cgi < 0.2.2 Yes
Application ruby-lang cgi < 0.3.5 Yes
Operating System fedoraproject fedora 35 Yes
Operating System fedoraproject fedora 36 Yes
Operating System fedoraproject fedora 37 Yes
Application ruby-lang ruby < 2.7.7 Yes
Application ruby-lang ruby < 3.0.5 Yes
Application ruby-lang ruby < 3.1.3 Yes

References