跳转到帖子

Amazon Linux 2023: CVE-2024-47220: Important priority package update for ruby3.2

recommended_posts

发布于
  • Members

Amazon Linux 2023: CVE-2024-47220: Important priority package update for ruby3.2

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:C/A:N)
Published
09/22/2024
Created
02/14/2025
Added
02/14/2025
Modified
02/14/2025

Description

An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production." A flaw was found in the webrick toolkit. This issue occurs because the server incorrectly handles requests with both Content-Length and Transfer-Encoding headers. This can allow an attacker to sneak in an extra request such as GET /admin after the normal request POST /user. As a result, unauthorized users can access restricted areas like /admin by POST /user.

Solution(s)

  • amazon-linux-2023-upgrade-ruby3-2
  • amazon-linux-2023-upgrade-ruby3-2-bundled-gems
  • amazon-linux-2023-upgrade-ruby3-2-bundled-gems-debuginfo
  • amazon-linux-2023-upgrade-ruby3-2-debuginfo
  • amazon-linux-2023-upgrade-ruby3-2-debugsource
  • amazon-linux-2023-upgrade-ruby3-2-default-gems
  • amazon-linux-2023-upgrade-ruby3-2-devel
  • amazon-linux-2023-upgrade-ruby3-2-doc
  • amazon-linux-2023-upgrade-ruby3-2-libs
  • amazon-linux-2023-upgrade-ruby3-2-libs-debuginfo
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-bigdecimal
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-bigdecimal-debuginfo
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-bundler
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-io-console
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-io-console-debuginfo
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-irb
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-json
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-json-debuginfo
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-minitest
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-power-assert
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-psych
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-psych-debuginfo
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-rake
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-rbs
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-rbs-debuginfo
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-rdoc
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-rexml
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-rss
  • amazon-linux-2023-upgrade-ruby3-2-rubygems
  • amazon-linux-2023-upgrade-ruby3-2-rubygems-devel
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-test-unit
  • amazon-linux-2023-upgrade-ruby3-2-rubygem-typeprof

References

  • https://attackerkb.com/topics/cve-2024-47220
  • CVE - 2024-47220
  • https://alas.aws.amazon.com/AL2023/ALAS-2024-743.html
  • 查看数 705
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…