Описание
Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). This vulnerability is patched in 3.0.9.1 and 2.2.8.1.
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support |
devel | not-affected | 2.2.7-1.1 |
esm-apps/bionic | not-affected | code not present |
esm-apps/focal | released | 2.0.7-2ubuntu0.1+esm5 |
esm-apps/jammy | released | 2.1.4-5ubuntu1+esm5 |
esm-apps/xenial | not-affected | code not present |
esm-infra-legacy/trusty | not-affected | code not present |
focal | ignored | end of standard support, was needed |
jammy | released | 2.1.4-5ubuntu1.1 |
mantic | released | 2.2.4-3ubuntu0.2 |
Показывать по
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). This vulnerability is patched in 3.0.9.1 and 2.2.8.1.
Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). This vulnerability is patched in 3.0.9.1 and 2.2.8.1.
Rack is a modular Ruby web server interface. Carefully crafted content ...
Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial)
Уязвимость модуля Rack интерпретатора языка программирования Ruby, связанная с использованием регулярного выражения c неэффективной вычислительной сложностью, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5.3 Medium
CVSS3