Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-27539

Опубликовано: 15 мар. 2023
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

There is a denial of service vulnerability in the header parsing component of Rack.

A denial of service vulnerability was found in rubygem-rack in how it parses headers. A carefully crafted input can cause header parsing to take an unexpected amount of time, possibly resulting in a denial of service.

Меры по смягчению последствий

Setting Regexp.timeout in Ruby 3.2 is a possible workaround.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp-backend-containerAffected
Red Hat 3scale API Management Platform 23scale-amp-zync-containerWill not fix
Red Hat Enterprise Linux 7pcsNot affected
Red Hat Storage 3rubygem-rackAffected
Red Hat Enterprise Linux 8pcsFixedRHSA-2023:308216.05.2023
Red Hat Enterprise Linux 8.4 Extended Update SupportpcsFixedRHSA-2023:196125.04.2023
Red Hat Enterprise Linux 8.6 Extended Update SupportpcsFixedRHSA-2023:340331.05.2023
Red Hat Enterprise Linux 9pcsFixedRHSA-2023:265209.05.2023
Red Hat Enterprise Linux 9.0 Extended Update SupportpcsFixedRHSA-2023:198125.04.2023
Red Hat Satellite 6.14 for RHEL 8rubygem-rackFixedRHSA-2023:681808.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2179649rubygem-rack: denial of service in header parsing

EPSS

Процентиль: 45%
0.00226
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
6 месяцев назад

There is a denial of service vulnerability in the header parsing component of Rack.

CVSS3: 5.3
nvd
6 месяцев назад

There is a denial of service vulnerability in the header parsing component of Rack.

CVSS3: 5.3
debian
6 месяцев назад

There is a denial of service vulnerability in the header parsing compo ...

suse-cvrf
около 2 лет назад

Security update for rubygem-rack

github
больше 2 лет назад

Possible Denial of Service Vulnerability in Rack's header parsing

EPSS

Процентиль: 45%
0.00226
Низкий

5.3 Medium

CVSS3