Ruby Improper Neutralization of CRLF Sequences in HTTP Headers (HTTP Response Splitting) Vulnerability - CVE-2017-17742 - Vulnerability Database

Ruby Improper Neutralization of CRLF Sequences in HTTP Headers (HTTP Response Splitting) Vulnerability - CVE-2017-17742

Medium
Reference: CVE-2017-17742
Title: Ruby Improper Neutralization of CRLF Sequences in HTTP Headers (HTTP Response Splitting) Vulnerability
Overview:

Ruby before 2.2.10 2.3.x before 2.3.7 2.4.x before 2.4.4 2.5.x before 2.5.1 and 2.6.0-preview1 allows an HTTP Response Splitting attack. An attacker can inject a crafted key and value into an HTTP response for the HTTP server of WEBrick.