Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 allows an HTTP Response Splitting attack. An attacker can inject a crafted key and value into an HTTP response for the HTTP server of WEBrick.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-04-03T00:00:00

Updated: 2023-04-30T00:00:00

Reserved: 2017-12-18T00:00:00


Link: CVE-2017-17742

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-04-03T22:29:00.383

Modified: 2023-04-30T23:15:44.367


Link: CVE-2017-17742

JSON object: View

cve-icon Redhat Information

No data.

CWE