Total vulnerabilities in the database
CRLF injection vulnerability in actionpack/lib/action_controller/response.rb in Ruby on Rails 2.3.x before 2.3.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the Content-Type header.
Software | From | Fixed in |
---|---|---|
rubyonrails / rails | 2.3.2 | 2.3.2.x |
rubyonrails / rails | 2.3.3 | 2.3.3.x |
rubyonrails / rails | 2.3.4 | 2.3.4.x |
rubyonrails / rails | 2.3.9 | 2.3.9.x |
rubyonrails / rails | 2.3.10 | 2.3.10.x |
rubyonrails / rails | 2.3.11 | 2.3.11.x |
rubyonrails / rails | 2.3.12 | 2.3.12.x |
![]() |
2.3.0 | 2.3.13 |