| Name | CVE-2021-41819 |
| Description | CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DLA-2853-1, DSA-5066-1, DSA-5067-1 |
| Debian Bugs | 1002995 |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| ruby2.3 | source | stretch | 2.3.3-1+deb9u11 | DLA-2853-1 | ||
| ruby2.3 | source | (unstable) | (unfixed) | |||
| ruby2.5 | source | buster | 2.5.5-3+deb10u4 | DSA-5066-1 | ||
| ruby2.5 | source | (unstable) | (unfixed) | |||
| ruby2.7 | source | bullseye | 2.7.4-1+deb11u1 | DSA-5067-1 | ||
| ruby2.7 | source | (unstable) | 2.7.5-1 | |||
| ruby3.0 | source | (unstable) | 3.0.3-1 | 1002995 |
Fixed in Ruby 3.0.3, 2.7.5, 2.6.9
https://www.ruby-lang.org/en/news/2021/11/24/cookie-prefix-spoofing-in-cgi-cookie-parse-cve-2021-41819/
Fixed by: https://github.com/ruby/cgi/commit/052eb3a828b0f99bca39cfd800f6c2b91307dbd5 (v0.3.1)