Back to search
CVE-2015-7519
Published: Jan 8, 2016
Modified: Aug 6, 2024
PUBLISHED
Description
agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
SUSE-SU-2015:2337
vendor-advisory
x_refsource_SUSE
https://blog.phusion.nl/2015/12/07/cve-2015-7519/
x_refsource_CONFIRM
https://puppet.com/security/cve/passenger-dec-2015-security-fixes
x_refsource_CONFIRM
[oss-security] 20151207 injecting environment variables into Phusion Passenger (CVE-2015-7519)
mailing-list
x_refsource_MLIST
https://bugzilla.suse.com/show_bug.cgi?id=956281
x_refsource_CONFIRM
[oss-security] 20151207 CVE-2015-7519: Phusion Passenger Header overwriting issue
mailing-list
x_refsource_MLIST
[debian-lts-announce] 20180627 [SECURITY] [DLA 1399-1] ruby-passenger security update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now