Lucene search

K
ibmIBM5400257711D52EF7392684EED315A454275F2246A67A6F3A0B001332F43C01DA
HistoryJul 26, 2021 - 4:53 p.m.

Security Bulletin: A security vulnerability in Ruby on Rails affects IBM Cloud Pak for Multicloud Management Infrastructure Management

2021-07-2616:53:38
www.ibm.com
9

0.002 Low

EPSS

Percentile

60.8%

Summary

A security vulnerability in Ruby on Rails affects IBM Cloud Pak for Multicloud Management Infrastructure Management.

Vulnerability Details

CVEID:CVE-2021-22902
**DESCRIPTION:**Ruby on Rails is vulnerable to a denial of service, caused by a use-after-free flaw in the in Action Dispatch. By sending specially-crafted Accept headers, a remote attacker could exploit this vulnerability to cause the mime type parser in Action Dispatch to do catastrophic backtracking in the regular expression engine.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/201281 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID:CVE-2021-22904
**DESCRIPTION:**Ruby on Rails is vulnerable to a denial of service, caused by a use-after-free flaw in the Token Authentication logic in Action Controller. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/201283 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Pak for Multicloud Management Infrastructure Management All

Remediation/Fixes

Upgrade to IBM Cloud Pak for Multicloud Management 2.3 latest fixpack by following the instructions in <https://www.ibm.com/docs/en/cloud-paks/cp-management/2.3.x?topic=installation-upgrade&gt;.

Workarounds and Mitigations

None

0.002 Low

EPSS

Percentile

60.8%