Improper Output Neutralization for Logs in Rack - CVE-2025-27111

 

Improper Output Neutralization for Logs in Rack - CVE-2025-27111

Published: March 17, 2025


Vulnerability identifier: #VU105795
CSH Severity: Medium
CVSS v4 BT: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2025-27111
CWE-ID: CWE-117
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to manipulate log entries.

The vulnerability exists due to improper input validation of the X-Sendfile-Type header in Rack::Sendfile when handling. A remote attacker can send specially crafted data containing newline characters via the affected header and manipulate log files.


Affected software

Rack
Debian Linux
SUSE Enterprise Server 15 SP3 Business Critical
SUSE Linux Enterprise High Availability Extension 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Ubuntu
openSUSE Leap
openEuler
Fedora
EasyApache
IBM License Metric Tool
IBM API Connect
ruby-rack (Ubuntu package)
ruby2.5-rubygem-rack-doc-1_6
ruby2.5-rubygem-rack-testsuite-1_6
ruby2.5-rubygem-rack-1_6
ruby2.5-rubygem-rack-testsuite
ruby2.5-rubygem-rack-doc
ruby2.5-rubygem-rack
rubygem-rack
rubygem-rack-help
ruby-rack (Debian package)

How to mitigate CVE-2025-27111

Install updates from vendor's website.

Rack - addressed in versions 2.2.12, 3.0.13, 3.1.11
EasyApache - addressed in versions 4 25-8, 4 25-9
IBM License Metric Tool - update to 9.2.39
IBM API Connect - update to 10.0.8.2 ifix2
ruby-rack (Ubuntu package) - addressed in versions Ubuntu Pro, 2.2.7-1ubuntu0.2, 2.2.7-1.1ubuntu0.1, 2.2.7-1.1ubuntu0.25.04.2
ruby2.5-rubygem-rack-doc-1_6 - update to 1.6.8-150000.3.6.1
ruby2.5-rubygem-rack-testsuite-1_6 - update to 1.6.8-150000.3.6.1
ruby2.5-rubygem-rack-1_6 - update to 1.6.8-150000.3.6.1
ruby2.5-rubygem-rack-testsuite - update to 2.0.8-150000.3.26.1
ruby2.5-rubygem-rack-doc - update to 2.0.8-150000.3.26.1
ruby2.5-rubygem-rack - update to 2.0.8-150000.3.26.1
rubygem-rack - update to 2.2.3.1-7
rubygem-rack-help - update to 2.2.3.1-7
ruby-rack (Debian package) - update to 2.2.13-1~deb12u1
rubygem-rack - addressed in versions 2.2.21-1.fc41, 2.2.21-9.fc42

External References

Related Security Bulletins