• Bug#1100444: ruby-rack: CVE-2025-27610

    From Salvatore Bonaccorso@21:1/5 to All on Thu Mar 13 23:20:01 2025
    Source: ruby-rack
    Version: 3.1.9-2
    Severity: important
    Tags: security upstream
    X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>

    Hi,

    The following vulnerability was published for ruby-rack.

    CVE-2025-27111[0]:
    | Rack is a modular Ruby web server interface. The Rack::Sendfile
    | middleware logs unsanitised header values from the X-Sendfile-Type
    | header. An attacker can exploit this by injecting escape sequences
    | (such as newline characters) into the header, resulting in log
    | injection. This vulnerability is fixed in 2.2.12, 3.0.13, and
    | 3.1.11.


    If you fix the vulnerability please also make sure to include the
    CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

    For further information see:

    [0] https://security-tracker.debian.org/tracker/CVE-2025-27111
    https://www.cve.org/CVERecord?id=CVE-2025-27111
    [1] https://github.com/rack/rack/security/advisories/GHSA-7wqh-767x-r66v

    Please adjust the affected versions in the BTS as needed.

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)