The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from IP addresses on a Class C network, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.
Advisories
Source ID Title
EUVD EUVD EUVD-2017-0159 The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from IP addresses on a Class C network, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.
Github GHSA Github GHSA GHSA-3vfw-7rcp-3xgm actionpack Improper Input Validation vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T23:22:27.754Z

Reserved: 2011-08-19T00:00:00Z

Link: CVE-2011-3187

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2011-08-29T18:55:01.707

Modified: 2025-04-11T00:51:21.963

Link: CVE-2011-3187

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses