FlawAtlas
Search the atlas
CVE-2015-7519 Low

CVE-2015-7519

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.

Exploit probability 2.4%
Published January 8, 2016
Required by Not available
Last source change April 10, 2026

02 / AFFECTED SOFTWARE

Affected packages

RubyGems passenger

129 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2015-7519

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.

View original source
Open Source Vulnerabilities GHSA-fxwv-953p-7qpf

`agent/Core/Controller/SendRequest.cpp` in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an `_` (underscore) character instead of a `-` (dash) character in an HTTP header, as demonstrated by an `X_User` header.

View original source

05 / REFERENCES

Further evidence