Ubuntu Security Update USN-7366-1: Rack vulnerabilities

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,770
Reaction score
74
Credits
-1,257
Nhật Thái Đỗ discovered that Rack incorrectly handled certain usernames. A remote attacker could possibly use this issue to perform CRLF injection. (CVE-2025-25184) Phạm Quang Minh discovered that Rack incorrectly handled certain headers. A remote attacker could possibly use this issue to perform log injection. (CVE-2025-27111) Phạm Quang Minh discovered that Rack did not properly handle relative file paths. A remote attacker could potentially exploit this to include local files that should have been inaccessible. (CVE-2025-27610)

Continue reading...
 


Follow Linux.org

Staff online

Members online


Top