Lucene search

K
osvGoogleOSV:CVE-2021-22902
HistoryJun 11, 2021 - 4:15 p.m.

CVE-2021-22902

2021-06-1116:15:11
Google
osv.dev
6

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.8%

The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic backtracking in the regular expression engine.

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.8%