Inconsistent interpretation of HTTP requests in WEBrick and Ruby - CVE-2020-25613

 

Inconsistent interpretation of HTTP requests in WEBrick and Ruby - CVE-2020-25613

Published: October 5, 2020 / Updated: March 30, 2022


Vulnerability identifier: #VU47333
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25613
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to preform HTTP request smuggling attacks.

The vulnerability exists due to improper validation of HTTP requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.

Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.


Affected software

WEBrick
Ruby
Gentoo Linux
Amazon Linux AMI
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for Power, little endian
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
Fedora
Red Hat Software Collections
ruby (Alpine package)
rh-ruby25-ruby (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
rubygem-net-telnet
rubygem-xmlrpc
rubygem-abrt
rubygem-abrt-doc
rubygem-io-console
rubygem-mysql2-doc
rubygem-mysql2
rubygem-power_assert
rubygem-did_you_mean
rubygem-pg
rubygem-pg-doc
rubygem-irb
rubygem-bigdecimal
rubygem-json
rubygem-openssl
rubygem-bundler
ruby2.1-debugsource
ruby2.1-stdlib
ruby2.1-debuginfo
ruby2.1
libruby2_1-2_1
ruby2.1-devel
libruby2_1-2_1-debuginfo
ruby2.1-stdlib-debuginfo
ruby2.3 (Ubuntu package)
libruby2.3 (Ubuntu package)
ruby2.5 (Ubuntu package)
libruby2.5 (Ubuntu package)
ruby-debuginfo
ruby
ruby-irb
ruby-help
ruby-devel
ruby-debugsource
ruby2.5-stdlib-debuginfo
ruby2.5-devel-extra
ruby2.5-devel
ruby2.5-stdlib
ruby2.5-debugsource
ruby2.5-debuginfo
ruby2.5
libruby2_5-2_5-debuginfo
libruby2_5-2_5
rh-ruby26-ruby (Red Hat package)
ruby2.7 (Ubuntu package)
libruby2.7 (Ubuntu package)
rh-ruby27-ruby (Red Hat package)
ruby-libs
ruby-default-gems
ruby-doc
rubygems
rubygems-devel
rubygem-mongo
rubygem-mongo-doc
rubygem-psych
rubygem-test-unit
rubygem-bson
rubygem-bson-doc
rubygem-minitest
rubygem-rdoc
rubygem-rake
EasyApache
Dell Secure Connect Gateway
IBM Cloud Foundry Migration Runtime

How to mitigate CVE-2020-25613

Install updates from vendor's website.

WEBrick - update to 1.6.1
Ruby - addressed in versions 2.5.9, 2.6.7, 2.7.2
ruby (Alpine package) - update to 2.7.2-r0
rh-ruby25-ruby (Red Hat package) - update to 2.5.9-9.el7
EasyApache - update to 4 2021-3-24
IBM Cloud Foundry Migration Runtime - update to 4.1.2
Dell Secure Connect Gateway - update to 5.12.00.10
rubygem-net-telnet - update to 0.1.1-2
rubygem-net-telnet - update to 0.2.0-136
rubygem-xmlrpc - update to 0.3.0-2
rubygem-xmlrpc - update to 0.3.0-136
rubygem-abrt - update to 0.4.0-1
rubygem-abrt-doc - update to 0.4.0-1
rubygem-io-console - update to 0.4.6-2
rubygem-mysql2-doc - update to 0.5.3-1
rubygem-mysql2 - update to 0.5.3-1
rubygem-io-console - update to 0.5.6-136
rubygem-power_assert - update to 1.1.1-2
rubygem-power_assert - update to 1.1.7-136
rubygem-did_you_mean - update to 1.2.0-2
rubygem-pg - update to 1.2.3-1.0.1
rubygem-pg-doc - update to 1.2.3-1.0.1
rubygem-irb - update to 1.2.6-136
rubygem-bigdecimal - update to 1.3.4-2
rubygem-bigdecimal - update to 2.0.0-136
rubygem-json - update to 2.1.0-2
rubygem-openssl - update to 2.1.2-2
rubygem-openssl - update to 2.1.2-136
rubygem-bundler - update to 2.1.4-136
ruby2.1-debugsource - update to 2.1.9-19.6.1
ruby2.1-stdlib - update to 2.1.9-19.6.1
ruby2.1-debuginfo - update to 2.1.9-19.6.1
ruby2.1 - update to 2.1.9-19.6.1
libruby2_1-2_1 - update to 2.1.9-19.6.1
ruby2.1-devel - update to 2.1.9-19.6.1
libruby2_1-2_1-debuginfo - update to 2.1.9-19.6.1
ruby2.1-stdlib-debuginfo - update to 2.1.9-19.6.1
rubygem-json - update to 2.3.0-136
ruby2.3 (Ubuntu package) - update to 2.3.1-2~ubuntu16.04.15
libruby2.3 (Ubuntu package) - update to 2.3.1-2~ubuntu16.04.15
ruby2.5 (Ubuntu package) - update to 2.5.1-1ubuntu1.8
libruby2.5 (Ubuntu package) - update to 2.5.1-1ubuntu1.8
ruby-debuginfo - update to 2.5.8-2
ruby - update to 2.5.8-2
ruby-irb - update to 2.5.8-2
ruby-help - update to 2.5.8-2
ruby-devel - update to 2.5.8-2
ruby-debugsource - update to 2.5.8-2
ruby2.5-stdlib-debuginfo - update to 2.5.8-4.14.1
ruby2.5-devel-extra - update to 2.5.8-4.14.1
ruby2.5-devel - update to 2.5.8-4.14.1
ruby2.5-stdlib - update to 2.5.8-4.14.1
ruby2.5-debugsource - update to 2.5.8-4.14.1
ruby2.5-debuginfo - update to 2.5.8-4.14.1
ruby2.5 - update to 2.5.8-4.14.1
libruby2_5-2_5-debuginfo - update to 2.5.8-4.14.1
libruby2_5-2_5 - update to 2.5.8-4.14.1
rh-ruby26-ruby (Red Hat package) - update to 2.6.7-119.el7
ruby2.7 (Ubuntu package) - addressed in versions 2.7.0-5ubuntu1.3, 2.7.1-3ubuntu1.2
libruby2.7 (Ubuntu package) - addressed in versions 2.7.0-5ubuntu1.3, 2.7.1-3ubuntu1.2
ruby - addressed in versions 2.7.2-135.fc32, 2.7.2-135.fc33
rh-ruby27-ruby (Red Hat package) - update to 2.7.3-129.el7
ruby-libs - update to 2.7.3-136
ruby-devel - update to 2.7.3-136
ruby - update to 2.7.3-136
ruby-default-gems - update to 2.7.3-136
ruby-doc - update to 2.7.3-136
rubygems - update to 2.7.6-2
rubygems-devel - update to 2.7.6-2
rubygem-mongo - update to 2.11.3-1
rubygem-mongo-doc - update to 2.11.3-1
rubygem-psych - update to 3.0.2-2
rubygem-psych - update to 3.1.0-136
rubygems-devel - update to 3.1.6-136
rubygems - update to 3.1.6-136
rubygem-test-unit - update to 3.2.7-2
rubygem-test-unit - update to 3.3.4-136
rubygem-bson - update to 4.8.1-1
rubygem-bson-doc - update to 4.8.1-1
rubygem-minitest - update to 5.10.3-2
rubygem-minitest - update to 5.13.0-136
rubygem-rdoc - update to 6.0.1.1-2
rubygem-rdoc - update to 6.2.1-136
rubygem-rake - update to 12.3.0-2
rubygem-rake - update to 13.0.1-136

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins