Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-27530

Опубликовано: 08 мар. 2023
Источник: redhat
CVSS3: 7.5

Описание

A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing to take longer than expected.

A flaw was found in rubygem-rack. This issue occurs in the Multipart MIME parsing code in Rack, which limits the number of file parts but does not limit the total number of parts that can be uploaded. Carefully crafted requests can abuse this and cause multipart parsing to take longer than expected, resulting in a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/fluentd-rhel8Affected
Red Hat 3scale API Management Platform 23scale-amp-zync-containerWill not fix
Red Hat Enterprise Linux 7pcsOut of support scope
Red Hat Storage 3rubygem-rackAffected
Red Hat Enterprise Linux 8pcsFixedRHSA-2023:308216.05.2023
Red Hat Enterprise Linux 8.4 Extended Update SupportpcsFixedRHSA-2023:196125.04.2023
Red Hat Enterprise Linux 8.6 Extended Update SupportpcsFixedRHSA-2023:340331.05.2023
Red Hat Enterprise Linux 9pcsFixedRHSA-2023:265209.05.2023
Red Hat Enterprise Linux 9.0 Extended Update SupportpcsFixedRHSA-2023:198125.04.2023
Red Hat Satellite 6.14 for RHEL 8rubygem-rackFixedRHSA-2023:681808.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2176477rubygem-rack: Denial of service in Multipart MIME parsing

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing to take longer than expected.

CVSS3: 7.5
nvd
больше 2 лет назад

A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing to take longer than expected.

CVSS3: 7.5
debian
больше 2 лет назад

A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and ...

suse-cvrf
больше 2 лет назад

Security update for rubygem-rack

CVSS3: 7.5
github
больше 2 лет назад

Rack has possible DoS Vulnerability in Multipart MIME parsing

7.5 High

CVSS3