Description
Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Server headers in requests, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.
Remediation
References
Related Vulnerabilities
Dolphin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-4333)
Undertow Improper Input Validation Vulnerability (CVE-2020-1757)
PrestaShop Improper Privilege Management Vulnerability (CVE-2013-6295)
WordPress Plugin LayerSlider Cross-Site Request Forgery (4.6.1)
Oracle Database Server CVE-2006-1873 Vulnerability (CVE-2006-1873)