Описание
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving files through Active Storage's proxy delivery mode, the proxy controller loads the entire requested byte range into memory before sending it. A request with a large or unbounded Range header (e.g. bytes=0-) could cause the server to allocate memory proportional to the file size, possibly resulting in a DoS vulnerability through memory exhaustion. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
A flaw was found in Rails Active Storage. A remote attacker can exploit this vulnerability by sending a request with a large or unbounded Range header, such as bytes=0-, when files are served through Active Storage's proxy delivery mode. This action can cause the server to allocate memory proportional to the file size, potentially leading to a Denial of Service (DoS) due to memory exhaustion.
Отчет
This vulnerability is rated a Moderate by Red Hat. Successful exploitation of this vulnerability depends on specific application deployment conditions and configurations within Active Storage, including the use of proxy delivery mode and the presence of sufficiently large files accessible to the attacker. Additionally, practical exploitation may require knowledge of valid file URLs and the ability to bypass common infrastructure protections such as reverse proxies or request limiting. As a result, achieving a reliable denial-of-service condition is not guaranteed in all environments and may require non-trivial effort.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat 3scale API Management Platform 2 | 3scale-amp20/system | Will not fix | ||
| Red Hat 3scale API Management Platform 2 | 3scale-amp21/system | Will not fix | ||
| Red Hat 3scale API Management Platform 2 | 3scale-amp21/zync | Affected | ||
| Red Hat 3scale API Management Platform 2 | 3scale-amp22/system | Will not fix | ||
| Red Hat 3scale API Management Platform 2 | 3scale-amp22/zync | Affected | ||
| Red Hat 3scale API Management Platform 2 | 3scale-amp24/system | Will not fix | ||
| Red Hat 3scale API Management Platform 2 | 3scale-amp24/zync | Will not fix | ||
| Red Hat 3scale API Management Platform 2 | 3scale-amp25/system | Will not fix | ||
| Red Hat 3scale API Management Platform 2 | 3scale-amp25/zync | Affected | ||
| Red Hat 3scale API Management Platform 2 | 3scale-amp26/system | Will not fix |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving files through Active Storage's proxy delivery mode, the proxy controller loads the entire requested byte range into memory before sending it. A request with a large or unbounded Range header (e.g. `bytes=0-`) could cause the server to allocate memory proportional to the file size, possibly resulting in a DoS vulnerability through memory exhaustion. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving files through Active Storage's proxy delivery mode, the proxy controller loads the entire requested byte range into memory before sending it. A request with a large or unbounded Range header (e.g. `bytes=0-`) could cause the server to allocate memory proportional to the file size, possibly resulting in a DoS vulnerability through memory exhaustion. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Active Storage allows users to attach cloud and local files in Rails a ...
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Уязвимость компонента Active Storage программной платформы Ruby on Rails, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5.9 Medium
CVSS3