← Back

CVE-2021-33621

nvd nist
Published: Nov 18, 2022Modified: Nov 4, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.

Affected (9)

2 products
Cgi
Ruby
1 product
Fedora
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Ruby Lang
Before 0.1.0.2
From 0.2.0 to 0.2.2
From 0.3.0 to 0.3.5
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 35
Version 36
Version 37
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Ruby Lang
From 2.7.0 to 2.7.7
From 3.0.0 to 3.0.5
From 3.1.0 to 3.1.3

References (15)

Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.