Логотип exploitDog
bind:"CVE-2024-26146" OR bind:"CVE-2024-25126" OR bind:"CVE-2024-26141"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-26146" OR bind:"CVE-2024-25126" OR bind:"CVE-2024-26141"

Количество 23

Количество 23

suse-cvrf логотип

SUSE-SU-2024:0946-1

больше 1 года назад

Security update for rubygem-rack-1_4

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0765-1

больше 1 года назад

Security update for rubygem-rack

EPSS: Низкий
oracle-oval логотип

ELSA-2024-2953

около 1 года назад

ELSA-2024-2953: pcs security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-2113

около 1 года назад

ELSA-2024-2113: pcs security update (MODERATE)

EPSS: Низкий
redos логотип

ROS-20240508-01

около 1 года назад

Множественные уязвимости rubygem-rack

CVSS3: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2024-26146

больше 1 года назад

Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. Ruby 3.2 has mitigations for this problem, so Rack applications using Ruby 3.2 or newer are unaffected. This vulnerability is fixed in 2.0.9.4, 2.1.4.4, 2.2.8.1, and 3.0.9.1.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2024-26146

больше 1 года назад

Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. Ruby 3.2 has mitigations for this problem, so Rack applications using Ruby 3.2 or newer are unaffected. This vulnerability is fixed in 2.0.9.4, 2.1.4.4, 2.2.8.1, and 3.0.9.1.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-26146

больше 1 года назад

Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. Ruby 3.2 has mitigations for this problem, so Rack applications using Ruby 3.2 or newer are unaffected. This vulnerability is fixed in 2.0.9.4, 2.1.4.4, 2.2.8.1, and 3.0.9.1.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-26146

больше 1 года назад

Rack is a modular Ruby web server interface. Carefully crafted headers ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-54rr-7fvw-6x8f

больше 1 года назад

Rack Header Parsing leads to Possible Denial of Service Vulnerability

EPSS: Низкий
fstec логотип

BDU:2024-01716

больше 1 года назад

Уязвимость модуля Rack интерпретатора языка программирования Ruby, связанная с использованием регулярного выражения c неэффективной вычислительной сложностью, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2024-26141

больше 1 года назад

Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with such large responses could lead to a denial of service issue. Vulnerable applications will use the `Rack::File` middleware or the `Rack::Utils.byte_ranges` methods (this includes Rails applications). The vulnerability is fixed in 3.0.9.1 and 2.2.8.1.

CVSS3: 5.8
EPSS: Низкий
redhat логотип

CVE-2024-26141

больше 1 года назад

Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with such large responses could lead to a denial of service issue. Vulnerable applications will use the `Rack::File` middleware or the `Rack::Utils.byte_ranges` methods (this includes Rails applications). The vulnerability is fixed in 3.0.9.1 and 2.2.8.1.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-26141

больше 1 года назад

Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with such large responses could lead to a denial of service issue. Vulnerable applications will use the `Rack::File` middleware or the `Rack::Utils.byte_ranges` methods (this includes Rails applications). The vulnerability is fixed in 3.0.9.1 and 2.2.8.1.

CVSS3: 5.8
EPSS: Низкий
debian логотип

CVE-2024-26141

больше 1 года назад

Rack is a modular Ruby web server interface. Carefully crafted Range h ...

CVSS3: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2024-25126

больше 1 года назад

Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). This vulnerability is patched in 3.0.9.1 and 2.2.8.1.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2024-25126

больше 1 года назад

Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). This vulnerability is patched in 3.0.9.1 and 2.2.8.1.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-25126

больше 1 года назад

Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). This vulnerability is patched in 3.0.9.1 and 2.2.8.1.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-25126

больше 1 года назад

Rack is a modular Ruby web server interface. Carefully crafted content ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xj5v-6v4g-jfw6

больше 1 года назад

Rack has possible DoS Vulnerability with Range Header

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
SUSE-SU-2024:0946-1

Security update for rubygem-rack-1_4

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0765-1

Security update for rubygem-rack

больше 1 года назад
oracle-oval логотип
ELSA-2024-2953

ELSA-2024-2953: pcs security update (MODERATE)

около 1 года назад
oracle-oval логотип
ELSA-2024-2113

ELSA-2024-2113: pcs security update (MODERATE)

около 1 года назад
redos логотип
ROS-20240508-01

Множественные уязвимости rubygem-rack

CVSS3: 5.8
около 1 года назад
ubuntu логотип
CVE-2024-26146

Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. Ruby 3.2 has mitigations for this problem, so Rack applications using Ruby 3.2 or newer are unaffected. This vulnerability is fixed in 2.0.9.4, 2.1.4.4, 2.2.8.1, and 3.0.9.1.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-26146

Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. Ruby 3.2 has mitigations for this problem, so Rack applications using Ruby 3.2 or newer are unaffected. This vulnerability is fixed in 2.0.9.4, 2.1.4.4, 2.2.8.1, and 3.0.9.1.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-26146

Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. Ruby 3.2 has mitigations for this problem, so Rack applications using Ruby 3.2 or newer are unaffected. This vulnerability is fixed in 2.0.9.4, 2.1.4.4, 2.2.8.1, and 3.0.9.1.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-26146

Rack is a modular Ruby web server interface. Carefully crafted headers ...

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-54rr-7fvw-6x8f

Rack Header Parsing leads to Possible Denial of Service Vulnerability

1%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-01716

Уязвимость модуля Rack интерпретатора языка программирования Ruby, связанная с использованием регулярного выражения c неэффективной вычислительной сложностью, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
1%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-26141

Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with such large responses could lead to a denial of service issue. Vulnerable applications will use the `Rack::File` middleware or the `Rack::Utils.byte_ranges` methods (this includes Rails applications). The vulnerability is fixed in 3.0.9.1 and 2.2.8.1.

CVSS3: 5.8
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-26141

Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with such large responses could lead to a denial of service issue. Vulnerable applications will use the `Rack::File` middleware or the `Rack::Utils.byte_ranges` methods (this includes Rails applications). The vulnerability is fixed in 3.0.9.1 and 2.2.8.1.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-26141

Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with such large responses could lead to a denial of service issue. Vulnerable applications will use the `Rack::File` middleware or the `Rack::Utils.byte_ranges` methods (this includes Rails applications). The vulnerability is fixed in 3.0.9.1 and 2.2.8.1.

CVSS3: 5.8
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-26141

Rack is a modular Ruby web server interface. Carefully crafted Range h ...

CVSS3: 5.8
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-25126

Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). This vulnerability is patched in 3.0.9.1 and 2.2.8.1.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-25126

Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). This vulnerability is patched in 3.0.9.1 and 2.2.8.1.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-25126

Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). This vulnerability is patched in 3.0.9.1 and 2.2.8.1.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-25126

Rack is a modular Ruby web server interface. Carefully crafted content ...

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xj5v-6v4g-jfw6

Rack has possible DoS Vulnerability with Range Header

0%
Низкий
больше 1 года назад

Уязвимостей на страницу