RHSA-2021:2584MediumCVSS 7.5
Red Hat Security Advisory: ruby:2.7 security, bug fix, and enhancement update
🔗 CVE IDs covered (2)
📋 Description
CVE-2020-25613 — ruby: Potential HTTP request smuggling in WEBrick CVE-2021-28965 — ruby: XML round-trip vulnerability in REXML
🎯 Affected products143
- Red Hat Enterprise Linux AppStream (v. 8)
- ruby-0:2.7.3-136.module+el8.4.0+10728+4c884998.aarch64 (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-0:2.7.3-136.module+el8.4.0+10728+4c884998.i686 (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-0:2.7.3-136.module+el8.4.0+10728+4c884998.ppc64le (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-0:2.7.3-136.module+el8.4.0+10728+4c884998.s390x (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-0:2.7.3-136.module+el8.4.0+10728+4c884998.src (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-0:2.7.3-136.module+el8.4.0+10728+4c884998.x86_64 (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-debuginfo-0:2.7.3-136.module+el8.4.0+10728+4c884998.aarch64 (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-debuginfo-0:2.7.3-136.module+el8.4.0+10728+4c884998.i686 (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-debuginfo-0:2.7.3-136.module+el8.4.0+10728+4c884998.ppc64le (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-debuginfo-0:2.7.3-136.module+el8.4.0+10728+4c884998.s390x (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-debuginfo-0:2.7.3-136.module+el8.4.0+10728+4c884998.x86_64 (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-debugsource-0:2.7.3-136.module+el8.4.0+10728+4c884998.aarch64 (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-debugsource-0:2.7.3-136.module+el8.4.0+10728+4c884998.i686 (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-debugsource-0:2.7.3-136.module+el8.4.0+10728+4c884998.ppc64le (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-debugsource-0:2.7.3-136.module+el8.4.0+10728+4c884998.s390x (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-debugsource-0:2.7.3-136.module+el8.4.0+10728+4c884998.x86_64 (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-default-gems-0:2.7.3-136.module+el8.4.0+10728+4c884998.noarch (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-devel-0:2.7.3-136.module+el8.4.0+10728+4c884998.aarch64 (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-devel-0:2.7.3-136.module+el8.4.0+10728+4c884998.i686 (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-devel-0:2.7.3-136.module+el8.4.0+10728+4c884998.ppc64le (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-devel-0:2.7.3-136.module+el8.4.0+10728+4c884998.s390x (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-devel-0:2.7.3-136.module+el8.4.0+10728+4c884998.x86_64 (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-doc-0:2.7.3-136.module+el8.4.0+10728+4c884998.noarch (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-libs-0:2.7.3-136.module+el8.4.0+10728+4c884998.aarch64 (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-libs-0:2.7.3-136.module+el8.4.0+10728+4c884998.i686 (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-libs-0:2.7.3-136.module+el8.4.0+10728+4c884998.ppc64le (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-libs-0:2.7.3-136.module+el8.4.0+10728+4c884998.s390x (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-libs-0:2.7.3-136.module+el8.4.0+10728+4c884998.x86_64 (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ruby-libs-debuginfo-0:2.7.3-136.module+el8.4.0+10728+4c884998.aarch64 (ruby:2.7) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- +113 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2021:2584
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1883623
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1947526
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1951999
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1952000
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_2584.json