Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-65f5-mfpf-vfhj

Опубликовано: 18 янв. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Denial of service via header parsing in Rack

There is a possible denial of service vulnerability in the Range header parsing component of Rack. This vulnerability has been assigned the CVE identifier CVE-2022-44570.

Versions Affected: >= 1.5.0 Not affected: None. Fixed Versions: 2.0.9.2, 2.1.4.2, 2.2.6.2, 3.0.0.1 Impact

Carefully crafted input can cause the Range header parsing component in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that deal with Range requests (such as streaming applications, or applications that serve files) may be impacted. Releases

The fixed releases are available at the normal locations. Workarounds

There are no feasible workarounds for this issue. Patches

To aid users who aren’t able to upgrade immediately we have provided patches for the two supported release series. They are in git-am format and consist of a single changeset.

2-0-Fix-ReDoS-in-Rack-Utils.get_byte_ranges.patch - Patch for 2.0 series 2-1-Fix-ReDoS-in-Rack-Utils.get_byte_ranges.patch - Patch for 2.1 series 2-2-Fix-ReDoS-in-Rack-Utils.get_byte_ranges.patch - Patch for 2.2 series 3-0-Fix-ReDoS-in-Rack-Utils.get_byte_ranges.patch - Patch for 3.0 series

Пакеты

Наименование

rack

rubygems
Затронутые версииВерсия исправления

>= 1.5.0, < 2.0.9.2

2.0.9.2

Наименование

rack

rubygems
Затронутые версииВерсия исправления

>= 2.1.0.0, < 2.1.4.2

2.1.4.2

Наименование

rack

rubygems
Затронутые версииВерсия исправления

>= 2.2.0.0, < 2.2.6.2

2.2.6.2

Наименование

rack

rubygems
Затронутые версииВерсия исправления

>= 3.0.0.0, < 3.0.4.1

3.0.4.1

EPSS

Процентиль: 84%
0.02366
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333
CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0. A Carefully crafted input can cause the Range header parsing component in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that deal with Range requests (such as streaming applications, or applications that serve files) may be impacted.

CVSS3: 7.5
redhat
больше 2 лет назад

A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0. A Carefully crafted input can cause the Range header parsing component in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that deal with Range requests (such as streaming applications, or applications that serve files) may be impacted.

CVSS3: 7.5
nvd
больше 2 лет назад

A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0. A Carefully crafted input can cause the Range header parsing component in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that deal with Range requests (such as streaming applications, or applications that serve files) may be impacted.

CVSS3: 7.5
debian
больше 2 лет назад

A denial of service vulnerability in the Range header parsing componen ...

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость компонента анализа заголовка Range модульного интерфейса между веб-серверами и веб-приложениями Rack, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 84%
0.02366
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333
CWE-400