Description
agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-394-1 | passenger security update |
Debian DLA |
DLA-1399-1 | ruby-passenger security update |
EUVD |
EUVD-2018-0595 | agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header. |
Github GHSA |
GHSA-fxwv-953p-7qpf | Phusion Passenger allows remote attackers to spoof headers |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T07:51:28.493Z
Reserved: 2015-09-29T00:00:00.000Z
Link: CVE-2015-7519
No data.
Status : Modified
Published: 2016-01-08T19:59:05.600
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-7519
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA