Inconsistent interpretation of HTTP requests in WEBrick and Ruby - CVE-2020-25613
Published: October 5, 2020 / Updated: March 30, 2022
Vulnerability details
The vulnerability allows a remote attacker to preform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
Affected software
Ruby
Gentoo Linux
Amazon Linux AMI
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for Power, little endian
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
Fedora
Red Hat Software Collections
ruby (Alpine package)
rh-ruby25-ruby (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
rubygem-net-telnet
rubygem-xmlrpc
rubygem-abrt
rubygem-abrt-doc
rubygem-io-console
rubygem-mysql2-doc
rubygem-mysql2
rubygem-power_assert
rubygem-did_you_mean
rubygem-pg
rubygem-pg-doc
rubygem-irb
rubygem-bigdecimal
rubygem-json
rubygem-openssl
rubygem-bundler
ruby2.1-debugsource
ruby2.1-stdlib
ruby2.1-debuginfo
ruby2.1
libruby2_1-2_1
ruby2.1-devel
libruby2_1-2_1-debuginfo
ruby2.1-stdlib-debuginfo
ruby2.3 (Ubuntu package)
libruby2.3 (Ubuntu package)
ruby2.5 (Ubuntu package)
libruby2.5 (Ubuntu package)
ruby-debuginfo
ruby
ruby-irb
ruby-help
ruby-devel
ruby-debugsource
ruby2.5-stdlib-debuginfo
ruby2.5-devel-extra
ruby2.5-devel
ruby2.5-stdlib
ruby2.5-debugsource
ruby2.5-debuginfo
ruby2.5
libruby2_5-2_5-debuginfo
libruby2_5-2_5
rh-ruby26-ruby (Red Hat package)
ruby2.7 (Ubuntu package)
libruby2.7 (Ubuntu package)
rh-ruby27-ruby (Red Hat package)
ruby-libs
ruby-default-gems
ruby-doc
rubygems
rubygems-devel
rubygem-mongo
rubygem-mongo-doc
rubygem-psych
rubygem-test-unit
rubygem-bson
rubygem-bson-doc
rubygem-minitest
rubygem-rdoc
rubygem-rake
EasyApache
Dell Secure Connect Gateway
IBM Cloud Foundry Migration Runtime
How to mitigate CVE-2020-25613
Ruby - addressed in versions 2.5.9, 2.6.7, 2.7.2
ruby (Alpine package) - update to 2.7.2-r0
rh-ruby25-ruby (Red Hat package) - update to 2.5.9-9.el7
EasyApache - update to 4 2021-3-24
IBM Cloud Foundry Migration Runtime - update to 4.1.2
Dell Secure Connect Gateway - update to 5.12.00.10
rubygem-net-telnet - update to 0.1.1-2
rubygem-net-telnet - update to 0.2.0-136
rubygem-xmlrpc - update to 0.3.0-2
rubygem-xmlrpc - update to 0.3.0-136
rubygem-abrt - update to 0.4.0-1
rubygem-abrt-doc - update to 0.4.0-1
rubygem-io-console - update to 0.4.6-2
rubygem-mysql2-doc - update to 0.5.3-1
rubygem-mysql2 - update to 0.5.3-1
rubygem-io-console - update to 0.5.6-136
rubygem-power_assert - update to 1.1.1-2
rubygem-power_assert - update to 1.1.7-136
rubygem-did_you_mean - update to 1.2.0-2
rubygem-pg - update to 1.2.3-1.0.1
rubygem-pg-doc - update to 1.2.3-1.0.1
rubygem-irb - update to 1.2.6-136
rubygem-bigdecimal - update to 1.3.4-2
rubygem-bigdecimal - update to 2.0.0-136
rubygem-json - update to 2.1.0-2
rubygem-openssl - update to 2.1.2-2
rubygem-openssl - update to 2.1.2-136
rubygem-bundler - update to 2.1.4-136
ruby2.1-debugsource - update to 2.1.9-19.6.1
ruby2.1-stdlib - update to 2.1.9-19.6.1
ruby2.1-debuginfo - update to 2.1.9-19.6.1
ruby2.1 - update to 2.1.9-19.6.1
libruby2_1-2_1 - update to 2.1.9-19.6.1
ruby2.1-devel - update to 2.1.9-19.6.1
libruby2_1-2_1-debuginfo - update to 2.1.9-19.6.1
ruby2.1-stdlib-debuginfo - update to 2.1.9-19.6.1
rubygem-json - update to 2.3.0-136
ruby2.3 (Ubuntu package) - update to 2.3.1-2~ubuntu16.04.15
libruby2.3 (Ubuntu package) - update to 2.3.1-2~ubuntu16.04.15
ruby2.5 (Ubuntu package) - update to 2.5.1-1ubuntu1.8
libruby2.5 (Ubuntu package) - update to 2.5.1-1ubuntu1.8
ruby-debuginfo - update to 2.5.8-2
ruby - update to 2.5.8-2
ruby-irb - update to 2.5.8-2
ruby-help - update to 2.5.8-2
ruby-devel - update to 2.5.8-2
ruby-debugsource - update to 2.5.8-2
ruby2.5-stdlib-debuginfo - update to 2.5.8-4.14.1
ruby2.5-devel-extra - update to 2.5.8-4.14.1
ruby2.5-devel - update to 2.5.8-4.14.1
ruby2.5-stdlib - update to 2.5.8-4.14.1
ruby2.5-debugsource - update to 2.5.8-4.14.1
ruby2.5-debuginfo - update to 2.5.8-4.14.1
ruby2.5 - update to 2.5.8-4.14.1
libruby2_5-2_5-debuginfo - update to 2.5.8-4.14.1
libruby2_5-2_5 - update to 2.5.8-4.14.1
rh-ruby26-ruby (Red Hat package) - update to 2.6.7-119.el7
ruby2.7 (Ubuntu package) - addressed in versions 2.7.0-5ubuntu1.3, 2.7.1-3ubuntu1.2
libruby2.7 (Ubuntu package) - addressed in versions 2.7.0-5ubuntu1.3, 2.7.1-3ubuntu1.2
ruby - addressed in versions 2.7.2-135.fc32, 2.7.2-135.fc33
rh-ruby27-ruby (Red Hat package) - update to 2.7.3-129.el7
ruby-libs - update to 2.7.3-136
ruby-devel - update to 2.7.3-136
ruby - update to 2.7.3-136
ruby-default-gems - update to 2.7.3-136
ruby-doc - update to 2.7.3-136
rubygems - update to 2.7.6-2
rubygems-devel - update to 2.7.6-2
rubygem-mongo - update to 2.11.3-1
rubygem-mongo-doc - update to 2.11.3-1
rubygem-psych - update to 3.0.2-2
rubygem-psych - update to 3.1.0-136
rubygems-devel - update to 3.1.6-136
rubygems - update to 3.1.6-136
rubygem-test-unit - update to 3.2.7-2
rubygem-test-unit - update to 3.3.4-136
rubygem-bson - update to 4.8.1-1
rubygem-bson-doc - update to 4.8.1-1
rubygem-minitest - update to 5.10.3-2
rubygem-minitest - update to 5.13.0-136
rubygem-rdoc - update to 6.0.1.1-2
rubygem-rdoc - update to 6.2.1-136
rubygem-rake - update to 12.3.0-2
rubygem-rake - update to 13.0.1-136
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- HTTP Request Smuggling in WEBrick
- Inconsistent interpretation of HTTP requests in ruby (Alpine package)
- Amazon Linux AMI update for ruby24
- Amazon Linux AMI update for ruby20
- Amazon Linux AMI update for ruby20
- cPanel EasyApache update for Ruby
- Red Hat Software Collections update for rh-ruby25-ruby
- Red Hat Software Collections update for rh-ruby27-ruby
- Red Hat Software Collections update for rh-ruby26-ruby
- Red Hat Enterprise Linux 8 update for the ruby:2.7 module
- Red Hat Enterprise Linux 8 update for the ruby:2.5 module
- Red Hat Enterprise Linux 8 update for the ruby:2.6 module
- Red Hat Enterprise Linux 8.1 update for the ruby:2.6 module
- Red Hat Enterprise Linux 8.2 update for the ruby:2.6 module
- SUSE update for ruby2.1
- Ubuntu update for ruby2.3
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Multiple vulnerabilities in IBM Cloud Foundry Migration Runtime
- SUSE update for ruby2.5
- Gentoo update for Ruby
- openEuler 20.03 LTS update for ruby
- Anolis OS update for ruby:2.7 module
- Fedora 33 update for ruby
- Fedora 32 update for ruby