Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-25613
Description:An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issue to bypass a reverse proxy (which also has a poor header check), which may lead to an HTTP Request Smuggling attack.
Test IDs: 1.3.6.1.4.1.25623.1.1.2.2021.1516   1.3.6.1.4.1.25623.1.1.2.2021.1228   1.3.6.1.4.1.25623.1.0.853733   1.3.6.1.4.1.25623.1.0.878464   1.3.6.1.4.1.25623.1.0.892392   1.3.6.1.4.1.25623.1.1.10.2020.0423   1.3.6.1.4.1.25623.1.1.1.2.2023.3408   1.3.6.1.4.1.25623.1.0.892391   1.3.6.1.4.1.25623.1.0.878503   1.3.6.1.4.1.25623.1.1.4.2021.0933.1   1.3.6.1.4.1.25623.1.1.2.2021.1450   1.3.6.1.4.1.25623.1.1.2.2020.2322  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-25613
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PFP3E7KXXT3H3KA6CBZPUOGA5VPFARRJ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YTZURYROG3FFED3TYCQOBV66BS4K6WOV/
https://security.gentoo.org/glsa/202401-27
https://hackerone.com/reports/965267
https://lists.debian.org/debian-lts-announce/2023/04/msg00033.html




© 1998-2025 E-Soft Inc. All rights reserved.