๐Ÿ” CVE Alert

CVE-2022-44572

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A denial of service vulnerability in the multipart parsing component of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1 and 3.0.0.1 could allow an attacker tocraft input that can cause RFC2183 multipart boundary parsing in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that parse multipart posts using Rack (virtually all Rails applications) are impacted.

CWE CWE-400
Vendor n/a
Product https://github.com/rack/rack
Published Feb 9, 2023
Last Updated Aug 3, 2024
Stay Ahead of the Next One

Get instant alerts for n/a https://github.com/rack/rack

Be the first to know when new unknown vulnerabilities affecting n/a https://github.com/rack/rack are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

n/a / https://github.com/rack/rack
2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackerone.com: https://hackerone.com/reports/1639882 debian.org: https://www.debian.org/security/2023/dsa-5530 security.netapp.com: https://security.netapp.com/advisory/ntap-20231208-0014/