2025-03-04 17:03:49 +00:00
{
"id" : "CVE-2025-27111" ,
"sourceIdentifier" : "security-advisories@github.com" ,
"published" : "2025-03-04T16:15:40.487" ,
"lastModified" : "2025-03-04T16:15:40.487" ,
2025-03-16 03:03:50 +00:00
"vulnStatus" : "Awaiting Analysis" ,
2025-03-04 17:03:49 +00:00
"cveTags" : [ ] ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs unsanitised header values from the X-Sendfile-Type header. An attacker can exploit this by injecting escape sequences (such as newline characters) into the header, resulting in log injection. This vulnerability is fixed in 2.2.12, 3.0.13, and 3.1.11."
2025-03-09 03:03:50 +00:00
} ,
{
"lang" : "es" ,
"value" : "Rack es una interfaz modular de servidor web Ruby. El middleware Rack::Sendfile registra valores de encabezado no depurados del encabezado X-Sendfile-Type. Un atacante puede aprovechar esto inyectando secuencias de escape (como caracteres de nueva l\u00ednea) en el encabezado, lo que da como resultado la inyecci\u00f3n de registros. Esta vulnerabilidad se corrigi\u00f3 en 2.2.12, 3.0.13 y 3.1.11."
2025-03-04 17:03:49 +00:00
}
] ,
"metrics" : {
"cvssMetricV40" : [
{
"source" : "security-advisories@github.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "4.0" ,
"vectorString" : "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" ,
"baseScore" : 6.9 ,
"baseSeverity" : "MEDIUM" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"attackRequirements" : "NONE" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"vulnConfidentialityImpact" : "NONE" ,
"vulnIntegrityImpact" : "LOW" ,
"vulnAvailabilityImpact" : "NONE" ,
"subConfidentialityImpact" : "NONE" ,
"subIntegrityImpact" : "NONE" ,
"subAvailabilityImpact" : "NONE" ,
"exploitMaturity" : "NOT_DEFINED" ,
"confidentialityRequirement" : "NOT_DEFINED" ,
"integrityRequirement" : "NOT_DEFINED" ,
"availabilityRequirement" : "NOT_DEFINED" ,
"modifiedAttackVector" : "NOT_DEFINED" ,
"modifiedAttackComplexity" : "NOT_DEFINED" ,
"modifiedAttackRequirements" : "NOT_DEFINED" ,
"modifiedPrivilegesRequired" : "NOT_DEFINED" ,
"modifiedUserInteraction" : "NOT_DEFINED" ,
"modifiedVulnConfidentialityImpact" : "NOT_DEFINED" ,
"modifiedVulnIntegrityImpact" : "NOT_DEFINED" ,
"modifiedVulnAvailabilityImpact" : "NOT_DEFINED" ,
"modifiedSubConfidentialityImpact" : "NOT_DEFINED" ,
"modifiedSubIntegrityImpact" : "NOT_DEFINED" ,
"modifiedSubAvailabilityImpact" : "NOT_DEFINED" ,
"Safety" : "NOT_DEFINED" ,
"Automatable" : "NOT_DEFINED" ,
"Recovery" : "NOT_DEFINED" ,
"valueDensity" : "NOT_DEFINED" ,
"vulnerabilityResponseEffort" : "NOT_DEFINED" ,
"providerUrgency" : "NOT_DEFINED"
}
}
]
} ,
"weaknesses" : [
{
"source" : "security-advisories@github.com" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-93"
} ,
{
"lang" : "en" ,
"value" : "CWE-117"
}
]
}
] ,
"references" : [
{
"url" : "https://github.com/rack/rack/commit/803aa221e8302719715e224f4476e438f2531a53" ,
"source" : "security-advisories@github.com"
} ,
{
"url" : "https://github.com/rack/rack/commit/aeac570bb8080ca7b53b7f2e2f67498be7ebd30b" ,
"source" : "security-advisories@github.com"
} ,
{
"url" : "https://github.com/rack/rack/commit/b13bc6bfc7506aca3478dc5ac1c2ec6fc53f82a3" ,
"source" : "security-advisories@github.com"
} ,
{
"url" : "https://github.com/rack/rack/security/advisories/GHSA-8cgq-6mh2-7j6v" ,
"source" : "security-advisories@github.com"
}
]
}