Description
agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.
Published: 2016-01-08
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-394-1 passenger security update
Debian DLA Debian DLA DLA-1399-1 ruby-passenger security update
EUVD EUVD EUVD-2018-0595 agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.
Github GHSA Github GHSA GHSA-fxwv-953p-7qpf Phusion Passenger allows remote attackers to spoof headers
History

No history.

Subscriptions

Phusionpassenger Phusion Passenger
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T07:51:28.493Z

Reserved: 2015-09-29T00:00:00.000Z

Link: CVE-2015-7519

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2016-01-08T19:59:05.600

Modified: 2026-05-06T22:30:45.220

Link: CVE-2015-7519

cve-icon Redhat

Severity : Moderate

Publid Date: 2015-12-07T00:00:00Z

Links: CVE-2015-7519 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses