class Railroader::CheckResponseSplitting

Warn about response splitting in Rails versions before 2.3.13 groups.google.com/group/rubyonrails-security/browse_thread/thread/6ffc93bde0298768

Public Instance Methods

run_check() click to toggle source
# File lib/railroader/checks/check_response_splitting.rb, line 10
def run_check
  if version_between?('2.3.0', '2.3.13')

    warn :warning_type => "Response Splitting",
      :warning_code => :CVE_2011_3186,
      :message => "Versions before 2.3.14 have a vulnerability content type handling allowing injection of headers: CVE-2011-3186",
      :confidence => :medium,
      :gem_info => gemfile_or_environment,
      :link_path => "https://groups.google.com/d/topic/rubyonrails-security/b_yTveAph2g/discussion"
  end
end