{"id":"GHSA-3vfw-7rcp-3xgm","summary":"actionpack Improper Input Validation vulnerability","details":"The `to_s` method in `actionpack/lib/action_dispatch/middleware/remote_ip.rb` in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from IP addresses on a Class C network, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.","aliases":["CVE-2011-3187"],"modified":"2024-11-29T05:35:28.609253Z","published":"2017-10-24T18:33:38Z","database_specific":{"github_reviewed_at":"2020-06-16T20:56:30Z","nvd_published_at":"2011-08-29T18:55:01Z","cwe_ids":["CWE-20"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-3187"},{"type":"WEB","url":"https://bugzilla.novell.com/show_bug.cgi?id=673010"},{"type":"PACKAGE","url":"https://github.com/rails/rails"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionpack/CVE-2011-3187.yml"},{"type":"WEB","url":"https://web.archive.org/web/20111209181000/http://archives.neohapsis.com/archives/fulldisclosure/2011-02/0337.html"},{"type":"WEB","url":"http://webservsec.blogspot.com/2011/02/ruby-on-rails-vulnerability.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/08/17/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/08/19/11"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/08/20/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/08/22/13"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/08/22/14"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/08/22/5"}],"affected":[{"package":{"name":"actionpack","ecosystem":"RubyGems","purl":"pkg:gem/actionpack"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.3.0"},{"fixed":"2.3.13"}]}],"versions":["2.3.10","2.3.11","2.3.12","2.3.2","2.3.3","2.3.4","2.3.5","2.3.6","2.3.7","2.3.8","2.3.8.pre1","2.3.9","2.3.9.pre"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-3vfw-7rcp-3xgm/GHSA-3vfw-7rcp-3xgm.json"}}],"schema_version":"1.9.0"}