๐Ÿ” CVE Alert

CVE-2023-27530

HIGH 7.5
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing to take longer than expected.

CWE CWE-400
Vendor n/a
Product https://github.com/rack/rack
Published Mar 10, 2023
Last Updated Oct 15, 2024
Stay Ahead of the Next One

Get instant alerts for n/a https://github.com/rack/rack

Be the first to know when new high vulnerabilities affecting n/a https://github.com/rack/rack are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

n/a / https://github.com/rack/rack
3.0.4.2, 2.2.6.3, 2.1.4.3, 2.0.9.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
discuss.rubyonrails.org: https://discuss.rubyonrails.org/t/cve-2023-27530-possible-dos-vulnerability-in-multipart-mime-parsing/82388 lists.debian.org: https://lists.debian.org/debian-lts-announce/2023/04/msg00017.html debian.org: https://www.debian.org/security/2023/dsa-5530 security.netapp.com: https://security.netapp.com/advisory/ntap-20231208-0015/