Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-44572
HistoryFeb 09, 2023 - 8:15 p.m.

Denial of service

2023-02-0920:15:00
PRIOn knowledge base
www.prio-n.com
6
denial of service
rack
multipart parsing
vulnerability
rfc2183
attack vector
rails applications

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.8%

A denial of service vulnerability in the multipart parsing component of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1 and 3.0.0.1 could allow an attacker tocraft input that can cause RFC2183 multipart boundary parsing in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that parse multipart posts using Rack (virtually all Rails applications) are impacted.