Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mpxf-gcw2-pw5q

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

actionpack Improper Input Validation vulnerability

actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching.

Пакеты

Наименование

actionpack

rubygems
Затронутые версииВерсия исправления

>= 3.0.0, < 3.2.16

3.2.16

Наименование

actionpack

rubygems
Затронутые версииВерсия исправления

>= 4.0.0, < 4.0.2

4.0.2

EPSS

Процентиль: 99%
0.70843
Высокий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 12 лет назад

actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching.

redhat
около 12 лет назад

actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching.

nvd
около 12 лет назад

actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching.

debian
около 12 лет назад

actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on ...

EPSS

Процентиль: 99%
0.70843
Высокий

Дефекты

CWE-20