Description
The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.
Related CPE's
a
ruby-lang
cgi
o
fedoraproject
fedora
a
ruby-lang
ruby
References
https://security.netapp.com/advisory/ntap-20221228-0004/
https://www.ruby-lang.org/en/news/2022/11/22/http-response-splitting-in-cgi-cve-2021-33621/
https://security.netapp.com/advisory/ntap-20221228-0004/
https://www.ruby-lang.org/en/news/2022/11/22/http-response-splitting-in-cgi-cve-2021-33621/
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8.8 · High
Information
Source identifier
Vulnerability status
Modified
Published
2022-11-18T22:15:18.987Z
3 years agoLast modified
2025-11-04T15:15:42.820Z
4 months ago