CVE-2024-47220
WEBrick HTTP Request Smuggling
Description
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
INFO
Published Date :
Sept. 22, 2024, 1:15 a.m.
Last Modified :
July 21, 2026, 2:16 p.m.
Remotely Exploit :
No
Source :
[email protected]
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
Solution
- Update the affected Ruby packages.
- Update the affected WEBrick package.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2024-47220 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2024-47220 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Rejected by [email protected]
Jul. 21, 2026
Action Type Old Value New Value -
CVE Modified by [email protected]
Jul. 21, 2026
Action Type Old Value New Value Changed Description An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production." Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. Removed Reference MITRE: https://github.com/ruby/webrick/issues/145 Removed Reference MITRE: https://github.com/ruby/webrick/issues/145#issuecomment-2369994610 Removed Reference MITRE: https://github.com/ruby/webrick/issues/145#issuecomment-2372838285 Removed Reference MITRE: https://github.com/ruby/webrick/pull/146/commits/d88321da45dcd230ac2b4585cad4833d6d5e8841 Removed Affected [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}] Removed Affected [{'cpes': ['cpe:2.3:a:ruby:webrick:*:*:*:*:*:*:*:*'], 'vendor': 'ruby', 'product': 'webrick', 'versions': [{'status': 'affected', 'version': '0', 'versionType': 'custom', 'lessThanOrEqual': '1.8.1'}], 'defaultStatus': 'unknown'}] Removed SSVC {'id': 'CVE-2024-47220', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'poc'}, {'automatable': 'yes'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-09-23T15:01:28.031073Z'} -
CVE Modified by [email protected]
Jul. 17, 2026
Action Type Old Value New Value Removed Tag disputed -
CVE Modified by [email protected]
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}] -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'cpes': ['cpe:2.3:a:ruby:webrick:*:*:*:*:*:*:*:*'], 'vendor': 'ruby', 'product': 'webrick', 'versions': [{'status': 'affected', 'version': '0', 'versionType': 'custom', 'lessThanOrEqual': '1.8.1'}], 'defaultStatus': 'unknown'}] Added SSVC {'id': 'CVE-2024-47220', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'poc'}, {'automatable': 'yes'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-09-23T15:01:28.031073Z'} -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jan. 09, 2025
Action Type Old Value New Value Removed CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Removed CWE CWE-444 -
CVE Modified by [email protected]
Sep. 25, 2024
Action Type Old Value New Value Added Reference MITRE https://github.com/ruby/webrick/issues/145#issuecomment-2372838285 [No types assigned] -
CVE Modified by [email protected]
Sep. 25, 2024
Action Type Old Value New Value Added Reference MITRE https://github.com/ruby/webrick/issues/145#issuecomment-2369994610 [No types assigned] Added Tag MITRE disputed -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Sep. 23, 2024
Action Type Old Value New Value Added CWE CISA-ADP CWE-444 Added CVSS V3.1 CISA-ADP AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N -
CVE Received by [email protected]
Sep. 22, 2024
Action Type Old Value New Value Added Description An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production." Added Reference MITRE https://github.com/ruby/webrick/issues/145 [No types assigned] Added Reference MITRE https://github.com/ruby/webrick/pull/146/commits/d88321da45dcd230ac2b4585cad4833d6d5e8841 [No types assigned]