CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
[
{
"id": "CVE-2021-41819-2f76299c",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"function_hash": "185553476159107413192269642060714357735",
"length": 658.0
},
"target": {
"file": "ext/cgi/escape/escape.c",
"function": "optimized_escape_html"
},
"source": "https://github.com/ruby/ruby/commit/f69aeb83146be640995753667fdd6c6f157527f5"
},
{
"id": "CVE-2021-41819-799f160e",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"line_hashes": [
"221608888545214764521643589590002473795",
"62837079863855754692353823286478885059",
"151633818343694841750591657495653307518",
"112628295566100827065348454738811594068"
],
"threshold": 0.9
},
"target": {
"file": "ext/cgi/escape/escape.c"
},
"source": "https://github.com/ruby/ruby/commit/f69aeb83146be640995753667fdd6c6f157527f5"
}
]