In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsThere is no fixed version for Debian:12
ruby-rack
.
Note: Versions mentioned in the description apply only to the upstream ruby-rack
package and not the ruby-rack
package as distributed by Debian
.
See How to fix?
for Debian:12
relevant fixed versions and status.
Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs unsanitised header values from the X-Sendfile-Type header. An attacker can exploit this by injecting escape sequences (such as newline characters) into the header, resulting in log injection. This vulnerability is fixed in 2.2.12, 3.0.13, and 3.1.11.