Lucene search

K
hackeroneOoooooo_qH1:1627159
HistoryJul 05, 2022 - 10:59 p.m.

Internet Bug Bounty: Rack CVE-2022-30122: Denial of Service Vulnerability in Rack Multipart Parsing

2022-07-0522:59:39
ooooooo_q
hackerone.com
$2400
50

0.001 Low

EPSS

Percentile

46.4%

ReDoS in Rack::Multipart::BROKEN_QUOTED and Rack::Multipart::BROKEN_UNQUOTED.

https://groups.google.com/g/ruby-security-ann/c/L2Axto442qk
> Carefully crafted multipart POST requests can cause Rack’s multipart parser to take much longer than expected, leading to a possible denial of service vulnerability.

Impact

When the client sends a specially crafted header, it occur ReDoS on the server side.
Servers that interpret Post data by default, like Rails, are affected.