GHSA-4vf4-qmvg-mh7h
HIGHCVE-2021-41819CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem prior to versions 0.3.1, 0.2.1, 0.1.1, and 0.1.0.1 for Ruby.
- Affected
- >=0, <2.6.9, >=2.7.0, <2.7.5, >=3.0.0, <3.0.3
- Fixed in
- 0.1.0.1
- Published
- 2022-01-21
- Source
- github