VYPR
Medium severity5.3NVD Advisory· Published Nov 26, 2019· Updated Jun 16, 2026

CVE-2011-3624

CVE-2011-3624

Description

Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Server headers in requests, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Ruby Lang/Rubycpe-rescue3 versions
    1.9.2+ 2 more
    • (no CPE)range: 1.9.2
    • cpe:2.3:a:ruby-lang:ruby:1.8.7:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.2:*:*:*:*:*:*:*
  • Range: <=1.9.2, <=1.8.7

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.