VYPR

apk package

chainguard/ruby3.2-webrick

pkg:apk/chainguard/ruby3.2-webrick

Vulnerabilities (2)

  • CVE-2024-47220Sep 22, 2024
    affected < 1.8.2-r0fixed 1.8.2-r0

    An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's po

  • CVE-2008-1145Mar 4, 2008
    affected < 0fixed 0

    Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when running on systems that support backslash (\) path separators or case-insensitive file names, allows remote attackers to access arbitrary files via (1) "..%5c"