CVE-2021-33621

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
18/11/2022
Last modified:
04/11/2025

Description

The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ruby-lang:cgi:*:*:*:*:*:ruby:*:* 0.1.0.2 (excluding)
cpe:2.3:a:ruby-lang:cgi:*:*:*:*:*:ruby:*:* 0.2.0 (including) 0.2.2 (excluding)
cpe:2.3:a:ruby-lang:cgi:*:*:*:*:*:ruby:*:* 0.3.0 (including) 0.3.5 (excluding)
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* 2.7.0 (including) 2.7.7 (excluding)
cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* 3.0.0 (including) 3.0.5 (excluding)
cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* 3.1.0 (including) 3.1.3 (excluding)