Lucene search

K
githubGitHub Advisory DatabaseGHSA-V882-CCJ6-JC48
HistoryMay 05, 2022 - 2:48 a.m.

Rack vulnerable to Denial of Service

2022-05-0502:48:31
GitHub Advisory Database
github.com
16

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

0.013 Low

EPSS

Percentile

85.8%

Unspecified vulnerability in Rack::Auth::AbstractRequest in Rack 1.1.x before 1.1.5, 1.2.x before 1.2.7, 1.3.x before 1.3.9, and 1.4.x before 1.4.4 allows remote attackers to cause a denial of service via unknown vectors related to “symbolized arbitrary strings.”

Affected configurations

Vulners
Node
rackrackRange<1.4.4
OR
rackrackRange<1.3.9
OR
rackrackRange<1.2.7
OR
rackrackRange<1.1.5
CPENameOperatorVersion
racklt1.4.4
racklt1.3.9
racklt1.2.7
racklt1.1.5

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

0.013 Low

EPSS

Percentile

85.8%