CVE-2021-33621: HTTP response splitting in CGI

We have released the cgi gem version 0.3.5, 0.2.2, and 0.1.0.2 that has a security fix for a HTTP response splitting vulnerability.
This vulnerability has been assigned the CVE identifier CVE-2021-33621.

Details

If an application that generates HTTP responses using the cgi gem with untrusted user input, an attacker can exploit it to inject a malicious HTTP response header and/or body.

Also, the contents for a CGI::Cookie object were not checked properly. If an application creates a CGI::Cookie object based on user input, an attacker may exploit it to inject invalid attributes in Set-Cookie header. We think such applications are unlikely, but we have included a change to check arguments for CGI::Cookie#initialize preventatively.

Please update the cgi gem to version 0.3.5, 0.2.2, and 0.1.0.2, or later. You can use gem update cgi to update it.
If you are using bundler, please add gem "cgi", ">= 0.3.5" to your Gemfile.

Affected versions

  • cgi gem 0.3.3 or before
  • cgi gem 0.2.1 or before
  • cgi gem 0.1.1 or 0.1.0.1 or 0.1.0

Credits

Thanks to Hiroshi Tokumaru for discovering this issue.

History

  • Originally published at 2022-11-22 02:00:00 (UTC)

Posted by mame on 22 Nov 2022

The best gift for anyone who wants to feel safer when they go online: Mozilla privacy products 

The best gift for anyone who wants to feel safer when they go online:  Mozilla privacy products 

The holidays are a wonderful time of the year where we are happily shopping for unique gifts for loved ones online. It also means we’re sharing our personal information online like giving out email addresses or phone numbers to sign up for discount programs or creating new accounts. Whenever we go online, we are asked […]

The post The best gift for anyone who wants to feel safer when they go online: Mozilla privacy products  appeared first on The Mozilla Blog.

Play Pokémon Scarlet and Violet on Android Mobile Tutorial (SKYLINE)

The latest build for Skyline Emulator for android can now play Pokemon Scarlet and Violet via mobile phone. If you are interested in knowing how is this possible, then please do watch this guide and follow all the steps at end of this video.

Copyright Disclaimer under Section 107 of the copyright act 1976, allowance is made for fair use for purposes such as criticism, comment, news reporting, scholarship, and research. Fair use is a use permitted by copyright statute that might otherwise be infringing. Non-profit, educational or personal use tips the balance in favour of fair use.

Official Site https://approms.com/pokesvmobile
Minimum Specs: Android 10 Arm 64 (Snapdragon 845)8GB RAM

#PokemonScarletAndroid #PokemonVioletAndroid #Skyline

❤️ હદય અને હદયના ધબકારા दिल और दिल की धड़कन Heart and beating of heart by Priyanka madam.

મોટાભાગના પ્રાણીઓમાં હૃદય એક સ્નાયુબદ્ધ અંગ છે. આ અંગ રુધિરાભિસરણ તંત્રની રક્તવાહિનીઓ દ્વારા લોહીને પમ્પ કરે છે. પમ્પ થયેલું લોહી શરીરમાં ઓક્સિજન અને પોષક તત્વોનું વહન કરે છે, જ્યારે કાર્બન ડાયોક્સાઇડ જેવા મેટાબોલિક કચરાને ફેફસામાં લઈ જાય છે. મનુષ્યોમાં, હૃદય લગભગ બંધ મુઠ્ઠી જેટલું હોય છે અને તે ફેફસાંની વચ્ચે, છાતીના મધ્ય ભાગમાં સ્થિત હોય છે.

https://dai.ly/x8fp4g3
https://dai.ly/x8fp4g4
https://dai.ly/x8fp4g5

https://www.youtube.com/channel/UCtfsUrX6JhKxSdtD3U04Xvw
https://www.youtube.com/watch?v=9v3MK6oTOeA&t=1s
https://www.youtube.com/watch?v=vxa6o_wrWnY
https://www.youtube.com/watch?v=T7mMcEYNKyQ
https://www.youtube.com/watch?v=BrakSGmQZB8&t=9s

#Contact us

Mobile : +917016525813
Whatsapp & Telegram : +919409077371
Email : hemangjoshi37a@gmail.com
Place a custom order on hjLabs.in : https://hjLabs.in
Please contribute your suggestions and corrections to support our efforts.
Thank you.
Buy us a coffee for $5 on PayPal ?
[![paypal](https://www.paypalobjects.com/en_US/i/btn/btn_donateCC_LG.gif)](https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=5JXC8VRCSUZWJ)

—————————————————————————————-

## Checkout Our Other Repositories:
https://github.com/hemangjoshi37a/pyPortMan
https://github.com/hemangjoshi37a/transformers_stock_prediction
https://github.com/hemangjoshi37a/TrendMaster
https://github.com/hemangjoshi37a/hjAlgos_notebooks
https://github.com/hemangjoshi37a/AutoCut
https://github.com/hemangjoshi37a/My_Projects
https://github.com/hemangjoshi37a/my_Arduino

## Checkout Our Other Products:
https://hjlabs.in/product/wifi-iot-led-display
https://hjlabs.in/product/swiboard-wifi-switch-board-iot-device
https://hjlabs.in/product/electric-bicycle
https://hjlabs.in/product/product-3d-design-with-solidworks/
https://hjlabs.in/product/automatic-wire-cutter-machine/
https://hjlabs.in/product/custom-algotrading-software-for-zerodha-and-angel-w-source-code/
https://play.google.com/store/apps/details?id=in.hjlabs.swiboard

## Some Cool Arduino and ESP8266 (or NodeMCU) IoT projects:
https://github.com/hemangjoshi37a/my_Arduino/tree/master/IoT_LED_over_ESP8266_NodeMCU
https://github.com/hemangjoshi37a/my_Arduino/tree/master/ESP8266_NodeMCU_BasicOTA
https://github.com/hemangjoshi37a/my_Arduino/tree/master/IoT_CSV_SD
https://github.com/hemangjoshi37a/my_Arduino/tree/master/Honeywell_I2C_Datalogger
https://github.com/hemangjoshi37a/my_Arduino/tree/master/IoT_Load_Cell_using_ESP8266_NodeMC
https://github.com/hemangjoshi37a/my_Arduino/tree/master/IoT_SSD1306_ESP8266_NodeMCU

## Checkout Our Awesome 3D GrabCAD Models:
https://grabcad.com/library/automatic-wire-cutter-machine-1
https://grabcad.com/library/esp-matrix-display-5mm-acrylic-box-1
https://grabcad.com/library/arcylic-bending-machine-w-hot-air-gun-1
https://grabcad.com/library/automatic-wire-cutter-stripper-1