vulnerability

Alma Linux: CVE-2021-41819: Moderate: ruby:2.5 security update (Multiple Advisories)

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
Jan 1, 2022
Added
May 4, 2022
Modified
Apr 4, 2024

Description

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

Solution(s)

alma-upgrade-rubyalma-upgrade-ruby-default-gemsalma-upgrade-ruby-develalma-upgrade-ruby-docalma-upgrade-ruby-irbalma-upgrade-ruby-libsalma-upgrade-rubygem-abrtalma-upgrade-rubygem-abrt-docalma-upgrade-rubygem-bigdecimalalma-upgrade-rubygem-bsonalma-upgrade-rubygem-bson-docalma-upgrade-rubygem-bundleralma-upgrade-rubygem-bundler-docalma-upgrade-rubygem-did_you_meanalma-upgrade-rubygem-io-consolealma-upgrade-rubygem-irbalma-upgrade-rubygem-jsonalma-upgrade-rubygem-minitestalma-upgrade-rubygem-mongoalma-upgrade-rubygem-mongo-docalma-upgrade-rubygem-mysql2alma-upgrade-rubygem-mysql2-docalma-upgrade-rubygem-net-telnetalma-upgrade-rubygem-opensslalma-upgrade-rubygem-pgalma-upgrade-rubygem-pg-docalma-upgrade-rubygem-power_assertalma-upgrade-rubygem-psychalma-upgrade-rubygem-rakealma-upgrade-rubygem-rbsalma-upgrade-rubygem-rdocalma-upgrade-rubygem-rexmlalma-upgrade-rubygem-rssalma-upgrade-rubygem-test-unitalma-upgrade-rubygem-typeprofalma-upgrade-rubygem-xmlrpcalma-upgrade-rubygemsalma-upgrade-rubygems-devel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.