Ruby Update
2578Warning Date
Severity Level
Warning Number
Target Sector
30 September, 2020
● High
2020-1853
All
Description:
Ruby has released a security update to address multiple vulnerabilities in the following versions:
- webrick gem 1.6.0
- or prior
- bundled versions of webrick in ruby 2.7.1
- or prior
- bundled versions of webrick in ruby 2.6.6
- or prior
- bundled versions of webrick in ruby 2.5.8
- or prior
Threats:
- An attacker could exploit this vulnerability by smuggling HTTP requests.
Best practice and Recommendations:
The CERT team encourages users to apply the necessary update according to the link below: