{"id":"GHSA-xq52-rv6w-397c","summary":"Directive injection when using dynamic overrides with user input","details":"### Impact\n\nIf user-supplied input was passed into `append/override_content_security_policy_directives`, a semicolon could be injected leading to directive injection.\n\nThis could be used to e.g. override a `script-src` directive. Duplicate directives are ignored and the first one wins. The directives in `secure_headers` are sorted alphabetically so they pretty much all come before `script-src`. A previously undefined directive would receive a value even if `SecureHeaders::OPT_OUT` was supplied.\n\nThe fixed versions will silently convert the semicolons to spaces and emit a deprecation warning when this happens. This will result in innocuous browser console messages if being exploited/accidentally used. In future releases, we will raise application errors resulting in 500s.\n\n\u003e Duplicate script-src directives detected.  All but the first instance will be ignored.\n\nSee https://www.w3.org/TR/CSP3/#parse-serialized-policy\n\n\u003e Note: In this case, the user agent SHOULD notify developers that a duplicate directive was ignored. A console warning might be appropriate, for example.\n\n### Patches\n\nDepending on what major version you are using, the fixed versions are 6.2.0, 5.1.0, 3.8.0.\n\n### Workarounds\n\nIf you are passing user input into the above methods, you could filter out the input:\n\n```ruby\noverride_content_security_policy_directives(:frame_src, [user_input.gsub(\";\", \" \")])\n```\n\n### References\n\nReported in https://github.com/twitter/secure_headers/issues/418\nhttps://www.w3.org/TR/CSP3/#parse-serialized-policy\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [this repo](https://github.com/twitter/secure_headers/issues/new)\n* DM @ndm on twitter ","aliases":["CVE-2020-5217"],"modified":"2026-05-07T05:01:28.824582135Z","published":"2020-01-23T02:28:11Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-01-23T02:12:03Z","nvd_published_at":null,"cwe_ids":["CWE-95"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/twitter/secure_headers/security/advisories/GHSA-xq52-rv6w-397c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-5217"},{"type":"WEB","url":"https://github.com/twitter/secure_headers/issues/418"},{"type":"WEB","url":"https://github.com/twitter/secure_headers/pull/421"},{"type":"WEB","url":"https://github.com/twitter/secure_headers/commit/936a160e3e9659737a9f9eafce13eea36b5c9fa3"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/secure_headers/CVE-2020-5217.yml"},{"type":"PACKAGE","url":"https://github.com/twitter/secure_headers"}],"affected":[{"package":{"name":"secure_headers","ecosystem":"RubyGems","purl":"pkg:gem/secure_headers"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0"},{"fixed":"6.2.0"}]}],"versions":["6.0.0","6.1.0","6.1.1","6.1.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/01/GHSA-xq52-rv6w-397c/GHSA-xq52-rv6w-397c.json"}},{"package":{"name":"secure_headers","ecosystem":"RubyGems","purl":"pkg:gem/secure_headers"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.1.0"}]}],"versions":["5.0.1","5.0.2","5.0.3","5.0.4","5.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/01/GHSA-xq52-rv6w-397c/GHSA-xq52-rv6w-397c.json"}},{"package":{"name":"secure_headers","ecosystem":"RubyGems","purl":"pkg:gem/secure_headers"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.8.0"}]}],"versions":["0.1.0","0.1.1","0.2.0","0.2.1","0.3.0","0.4.0","0.4.1","0.4.2","0.4.3","0.5.0","1.0.0","1.1.0","1.1.1","1.2.0","1.3.0","1.3.1","1.3.2","1.3.3","1.3.4","1.4.0","1.4.1","2.0.0","2.0.0.pre","2.0.0.pre2","2.0.1","2.0.2","2.1.0","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4","2.3.0","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.5.0","2.5.1","2.5.2","2.5.3","3.0.0","3.0.0.pre","3.0.0.pre1","3.0.0.pre2","3.0.0.pre3","3.0.0.rc1","3.0.1","3.0.2","3.0.3","3.1.0","3.1.1","3.1.2","3.2.0","3.3.0","3.3.1","3.3.2","3.4.0","3.4.1","3.5.0","3.5.0.pre","3.5.1","3.6.0","3.6.1","3.6.2","3.6.3","3.6.4","3.6.5","3.6.6","3.6.7","3.7.0","3.7.1","3.7.2","3.7.3","3.7.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/01/GHSA-xq52-rv6w-397c/GHSA-xq52-rv6w-397c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}