Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rgr4-9jh5-j4j6

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

Rack vulnerable to Denial of Service via large parameter depth request

lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.

Пакеты

Наименование

rack

rubygems
Затронутые версииВерсия исправления

>= 1.5.0, < 1.5.4

1.5.4

Наименование

rack

rubygems
Затронутые версииВерсия исправления

>= 1.6.0, < 1.6.2

1.6.2

Наименование

rack

rubygems
Затронутые версииВерсия исправления

>= 1.4.0, < 1.4.6

1.4.6

EPSS

Процентиль: 94%
0.1408
Средний

Связанные уязвимости

ubuntu
больше 10 лет назад

lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.

redhat
больше 10 лет назад

lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.

nvd
больше 10 лет назад

lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.

debian
больше 10 лет назад

lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used ...

suse-cvrf
около 10 лет назад

Security update for rubygem-rack-1_4

EPSS

Процентиль: 94%
0.1408
Средний