Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7581

Опубликовано: 25 янв. 2016
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

actionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in Ruby on Rails 4.x before 4.2.5.1 and 5.x before 5.0.0.beta1.1 allows remote attackers to cause a denial of service (superfluous caching and memory consumption) by leveraging an application's use of a wildcard controller route.

A flaw was found in the Action Pack component's caching of controller references. An attacker could use this flaw to cause unbounded memory growth, potentially resulting in a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5.2ruby193-rubygem-actionpackNot affected
CloudForms Management Engine 5.3ruby193-rubygem-actionpackNot affected
Red Hat Software Collectionsruby193-rubygem-actionpackNot affected
Red Hat Subscription Asset Managerruby193-rubygem-actionpackNot affected
Red Hat Subscription Asset Managerrubygem-actionpackNot affected
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-ror41-rubygem-actionpackFixedRHSA-2016:029624.02.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-ror41-rubygem-actionviewFixedRHSA-2016:029624.02.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-ror41-rubygem-activemodelFixedRHSA-2016:029624.02.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-ror41-rubygem-activerecordFixedRHSA-2016:029624.02.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-ror41-rubygem-activesupportFixedRHSA-2016:029624.02.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=1301981rubygem-actionpack: Object leak vulnerability for wildcard controller routes in Action Pack

EPSS

Процентиль: 92%
0.09055
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 10 лет назад

actionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in Ruby on Rails 4.x before 4.2.5.1 and 5.x before 5.0.0.beta1.1 allows remote attackers to cause a denial of service (superfluous caching and memory consumption) by leveraging an application's use of a wildcard controller route.

CVSS3: 7.5
nvd
почти 10 лет назад

actionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in Ruby on Rails 4.x before 4.2.5.1 and 5.x before 5.0.0.beta1.1 allows remote attackers to cause a denial of service (superfluous caching and memory consumption) by leveraging an application's use of a wildcard controller route.

CVSS3: 7.5
debian
почти 10 лет назад

actionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in ...

CVSS3: 7.5
github
больше 8 лет назад

actionpack is vulnerable to denial of service because of a wildcard controller route

fstec
почти 10 лет назад

Уязвимость программной платформы Ruby on Rails, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 92%
0.09055
Низкий

4.3 Medium

CVSS2