CVE-2025-25184 | rack up to 2.2.10/3.0.11/3.1.10 Rack::CommonLogger env['REMOTE_USER'] crlf injection (GHSA-7g2v-jj9q-g3rg / Nessus ID 230824)
A vulnerability classified as problematic was found in rack up to 2.2.10/3.0.11/3.1.10. The affected element is the function Rack::CommonLogger. The manipulation of the argument env['REMOTE_USER'] results in crlf injection.
This vulnerability is cataloged as CVE-2025-25184. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.