Логотип exploitDog
bind:CVE-2024-39316
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-39316

Количество 4

Количество 4

ubuntu логотип

CVE-2024-39316

больше 1 года назад

Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.5, Regular Expression Denial of Service (ReDoS) vulnerability exists in the `Rack::Request::Helpers` module when parsing HTTP Accept headers. This vulnerability can be exploited by an attacker sending specially crafted `Accept-Encoding` or `Accept-Language` headers, causing the server to spend excessive time processing the request and leading to a Denial of Service (DoS). The fix for CVE-2024-26146 was not applied to the main branch and thus while the issue was fixed for the Rack v3.0 release series, it was not fixed in the v3.1 release series until v3.1.5. Users of versions on the 3.1 branch should upgrade to version 3.1.5 to receive the fix.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-39316

больше 1 года назад

Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.5, Regular Expression Denial of Service (ReDoS) vulnerability exists in the `Rack::Request::Helpers` module when parsing HTTP Accept headers. This vulnerability can be exploited by an attacker sending specially crafted `Accept-Encoding` or `Accept-Language` headers, causing the server to spend excessive time processing the request and leading to a Denial of Service (DoS). The fix for CVE-2024-26146 was not applied to the main branch and thus while the issue was fixed for the Rack v3.0 release series, it was not fixed in the v3.1 release series until v3.1.5. Users of versions on the 3.1 branch should upgrade to version 3.1.5 to receive the fix.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-39316

больше 1 года назад

Rack is a modular Ruby web server interface. Starting in version 3.1.0 ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-cj83-2ww7-mvq7

больше 1 года назад

Rack ReDoS Vulnerability in HTTP Accept Headers Parsing

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-39316

Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.5, Regular Expression Denial of Service (ReDoS) vulnerability exists in the `Rack::Request::Helpers` module when parsing HTTP Accept headers. This vulnerability can be exploited by an attacker sending specially crafted `Accept-Encoding` or `Accept-Language` headers, causing the server to spend excessive time processing the request and leading to a Denial of Service (DoS). The fix for CVE-2024-26146 was not applied to the main branch and thus while the issue was fixed for the Rack v3.0 release series, it was not fixed in the v3.1 release series until v3.1.5. Users of versions on the 3.1 branch should upgrade to version 3.1.5 to receive the fix.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-39316

Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.5, Regular Expression Denial of Service (ReDoS) vulnerability exists in the `Rack::Request::Helpers` module when parsing HTTP Accept headers. This vulnerability can be exploited by an attacker sending specially crafted `Accept-Encoding` or `Accept-Language` headers, causing the server to spend excessive time processing the request and leading to a Denial of Service (DoS). The fix for CVE-2024-26146 was not applied to the main branch and thus while the issue was fixed for the Rack v3.0 release series, it was not fixed in the v3.1 release series until v3.1.5. Users of versions on the 3.1 branch should upgrade to version 3.1.5 to receive the fix.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-39316

Rack is a modular Ruby web server interface. Starting in version 3.1.0 ...

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-cj83-2ww7-mvq7

Rack ReDoS Vulnerability in HTTP Accept Headers Parsing

CVSS3: 6.5
1%
Низкий
больше 1 года назад

Уязвимостей на страницу