{"schema_version":"1.7.3","id":"GHSA-6f62-3596-g6w7","published":"2024-09-22T03:30:30Z","modified":"2026-02-04T04:37:53.734762Z","aliases":["CVE-2024-47220"],"related":["CGA-26g8-c8gp-gjfh"],"summary":"HTTP Request Smuggling in ruby webrick","details":"An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., \"GET /admin HTTP/1.1\\r\\n\" inside of a \"POST /user HTTP/1.1\\r\\n\" request. NOTE: the supplier's position is \"Webrick should not be used in production.\"","affected":[{"package":{"name":"webrick","ecosystem":"RubyGems","purl":"pkg:gem/webrick"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.2"}]}],"versions":["1.3.1","1.4.0","1.4.0.beta1","1.4.1","1.4.2","1.4.3","1.4.4","1.5.0","1.5.1","1.6.0","1.6.1","1.7.0","1.8.0","1.8.1"],"database_specific":{"last_known_affected_version_range":"<= 1.8.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-6f62-3596-g6w7/GHSA-6f62-3596-g6w7.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47220"},{"type":"WEB","url":"https://github.com/ruby/webrick/issues/145"},{"type":"WEB","url":"https://github.com/ruby/webrick/issues/145#issuecomment-2369994610"},{"type":"WEB","url":"https://github.com/ruby/webrick/issues/145#issuecomment-2372838285"},{"type":"WEB","url":"https://github.com/ruby/webrick/pull/146/commits/d88321da45dcd230ac2b4585cad4833d6d5e8841"},{"type":"WEB","url":"https://github.com/ruby/webrick/commit/f5faca9222541591e1a7c3c97552ebb0c92733c7"},{"type":"PACKAGE","url":"https://github.com/ruby/webrick"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/webrick/CVE-2024-47220.yml"}],"database_specific":{"cwe_ids":["CWE-444"],"github_reviewed":true,"github_reviewed_at":"2024-09-23T20:43:55Z","nvd_published_at":"2024-09-22T01:15:11Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}