Описание
There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate to the request size.
Отчет
OpenShift Enterprise and Red Hat OpenStack Platform optools both ship rubygem-rack 1.5.2, which is not affected by this flaw. Red Hat Subscription Asset Manager uses rubygem-rack 1.4.5, and is not affected by this flaw. Red Hat Update Infrastructure ships rubygem-rack version 1.4.2, which is not affected by this flaw. Red Hat CloudForms versions 4.5 and 4.6 ship rack version 2.0.3, which is not affected by this flaw; while Red Hat CloudForms version 4.7 ships rack version 2.0.6, which already contains the fix for this flaw.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| CloudForms Management Engine 5 | cfme-amazon-smartstate | Not affected | ||
| CloudForms Management Engine 5 | cfme-gemset | Not affected | ||
| CloudForms Management Engine 5 | dbus-api-service | Not affected | ||
| Red Hat OpenShift Container Platform 3.2 | rubygem-rack | Not affected | ||
| Red Hat OpenShift Container Platform 3.3 | rubygem-rack | Not affected | ||
| Red Hat OpenShift Container Platform 3.4 | rubygem-rack | Not affected | ||
| Red Hat OpenShift Enterprise 3.1 | rubygem-rack | Not affected | ||
| Red Hat OpenStack Platform 10 (Newton) Operational Tools | rubygem-rack | Not affected | ||
| Red Hat OpenStack Platform 12 (Pike) Operational Tools | rubygem-rack | Not affected | ||
| Red Hat OpenStack Platform 13 (Queens) Operational Tools | rubygem-rack | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate to the request size.
There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate to the request size.
There is a possible DoS vulnerability in the multipart parser in Rack ...
Уязвимость модуля Rack интерпретатора языка программирования Ruby, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5.3 Medium
CVSS3