Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ffpv-c4hm-3x6v

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

actionpack is vulnerable to denial of service via a crafted HTTP Accept header

actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly restrict use of the MIME type cache, which allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP Accept header.

Пакеты

Наименование

actionpack

rubygems
Затронутые версииВерсия исправления

>= 4.2.0, <= 4.2.5.0

4.2.5.1

Наименование

actionpack

rubygems
Затронутые версииВерсия исправления

<= 3.2.22.0

3.2.22.1

Наименование

actionpack

rubygems
Затронутые версииВерсия исправления

>= 4.0.0, <= 4.1.14.0

4.1.14.1

EPSS

Процентиль: 91%
0.06145
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 10 лет назад

actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly restrict use of the MIME type cache, which allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP Accept header.

redhat
около 10 лет назад

actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly restrict use of the MIME type cache, which allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP Accept header.

CVSS3: 7.5
nvd
почти 10 лет назад

actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly restrict use of the MIME type cache, which allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP Accept header.

CVSS3: 7.5
debian
почти 10 лет назад

actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Rub ...

fstec
почти 10 лет назад

Уязвимость программной платформы Ruby on Rails, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 91%
0.06145
Низкий

7.5 High

CVSS3