CVE-2021-41819
Public on 2022-01-01
        Modified on 2024-02-23
        
      Description
            
              CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
            
          Severity
          
          See what this means
        CVSS v3 Base Score
          
          See breakdown
        Affected Packages
| Platform | Package | Release Date | Advisory | Status | 
|---|---|---|---|---|
| Amazon Linux 1 | ruby | No Fix Planned | ||
| Amazon Linux 2 - Core | ruby | 2024-03-04 | ALAS2-2024-2486 | Fixed | 
| Amazon Linux 2 - Ruby2.6 Extra | ruby | 2023-09-25 | ALAS2RUBY2.6-2023-002 | Fixed | 
| Amazon Linux 2 - Ruby3.0 Extra | ruby | 2023-09-25 | ALAS2RUBY3.0-2023-003 | Fixed | 
| Amazon Linux 2023 | ruby3.2 | Not Affected | 
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 6.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N | 
| NVD | CVSSv2 | 5.0 | AV:N/AC:L/Au:N/C:N/I:P/A:N | 
| NVD | CVSSv3 | 7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |