Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-26141

Опубликовано: 29 фев. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.8

Описание

Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with such large responses could lead to a denial of service issue. Vulnerable applications will use the Rack::File middleware or the Rack::Utils.byte_ranges methods (this includes Rails applications). The vulnerability is fixed in 3.0.9.1 and 2.2.8.1.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

2.2.7-1.1
esm-apps/bionic

released

1.6.4-4ubuntu0.2+esm6
esm-apps/focal

released

2.0.7-2ubuntu0.1+esm5
esm-apps/jammy

released

2.1.4-5ubuntu1+esm5
esm-apps/xenial

released

1.6.4-3ubuntu0.2+esm6
esm-infra-legacy/trusty

not-affected

1.5.2-3+deb8u3ubuntu1~esm8
focal

ignored

end of standard support, was needed
jammy

released

2.1.4-5ubuntu1.1
mantic

released

2.2.4-3ubuntu0.1

Показывать по

EPSS

Процентиль: 49%
0.00253
Низкий

5.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
больше 1 года назад

Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with such large responses could lead to a denial of service issue. Vulnerable applications will use the `Rack::File` middleware or the `Rack::Utils.byte_ranges` methods (this includes Rails applications). The vulnerability is fixed in 3.0.9.1 and 2.2.8.1.

CVSS3: 5.8
nvd
больше 1 года назад

Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with such large responses could lead to a denial of service issue. Vulnerable applications will use the `Rack::File` middleware or the `Rack::Utils.byte_ranges` methods (this includes Rails applications). The vulnerability is fixed in 3.0.9.1 and 2.2.8.1.

CVSS3: 5.8
debian
больше 1 года назад

Rack is a modular Ruby web server interface. Carefully crafted Range h ...

github
больше 1 года назад

Rack has possible DoS Vulnerability with Range Header

CVSS3: 5.8
fstec
больше 1 года назад

Уязвимость интерфейса модуля Rack интерпретатора языка программирования Ruby, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 49%
0.00253
Низкий

5.8 Medium

CVSS3