Описание
actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the :text option to the render method, which allows remote attackers to cause a denial of service (memory consumption) by including these strings in headers.
Отчет
Red Hat OpenShift Enterprise 1.2 is now in Production 1 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat OpenShift Enterprise Life Cycle: https://access.redhat.com/site/support/policy/updates/openshift.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Enterprise 1 | ruby193-rubygem-actionpack | Will not fix | ||
| Red Hat OpenStack Platform 3 | ruby193-rubygem-actionpack | Affected | ||
| Red Hat OpenStack Platform 4 | ruby193-rubygem-actionpack | Affected | ||
| Red Hat Satellite 6 | ruby193-rubygem-actionpack | Affected | ||
| Red Hat Software Collections | ror40-rubygem-actionpack | Not affected | ||
| Red Hat Subscription Asset Manager | ruby193-rubygem-actionpack | Will not fix | ||
| CloudForms Management Engine 5.x | cfme | Fixed | RHSA-2014:0215 | 11.03.2014 |
| CloudForms Management Engine 5.x | ruby193-ruby | Fixed | RHSA-2014:0215 | 11.03.2014 |
| CloudForms Management Engine 5.x | ruby193-rubygem-actionpack | Fixed | RHSA-2014:0215 | 11.03.2014 |
| CloudForms Management Engine 5.x | ruby193-rubygem-amq-protocol | Fixed | RHSA-2014:0215 | 11.03.2014 |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS2
Связанные уязвимости
actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the :text option to the render method, which allows remote attackers to cause a denial of service (memory consumption) by including these strings in headers.
actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the :text option to the render method, which allows remote attackers to cause a denial of service (memory consumption) by including these strings in headers.
actionpack/lib/action_view/template/text.rb in Action View in Ruby on ...
EPSS
5 Medium
CVSS2