Описание
encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by sending an HTTP request with an extremely long "id" parameter.
Ссылки
- ExploitThird Party Advisory
- Patch
- ExploitVendor Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Patch
- ExploitVendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.0 (исключая)
Одно из
cpe:2.3:a:diaconou:encodedid\:\:rails:*:*:*:*:*:ruby:*:*
cpe:2.3:a:diaconou:encodedid\:\:rails:1.0.0:-:*:*:*:ruby:*:*
cpe:2.3:a:diaconou:encodedid\:\:rails:1.0.0:beta1:*:*:*:ruby:*:*
EPSS
Процентиль: 59%
0.00376
Низкий
7.5 High
CVSS3
Дефекты
CWE-400
CWE-770
Связанные уязвимости
CVSS3: 7.5
github
больше 2 лет назад
encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs
EPSS
Процентиль: 59%
0.00376
Низкий
7.5 High
CVSS3
Дефекты
CWE-400
CWE-770