Lucene search

K
rubygemsRubySecRUBY:RACK-2013-0184-89327
HistoryJan 12, 2013 - 8:00 p.m.

CVE-2013-0184 rubygem-rack: Rack::Auth::AbstractRequest DoS

2013-01-1220:00:00
RubySec
rubysec.com
11

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

0.013 Low

EPSS

Percentile

85.8%

Unspecified vulnerability in Rack::Auth::AbstractRequest in Rack 1.1.x
before 1.1.5, 1.2.x before 1.2.7, 1.3.x before 1.3.9, and 1.4.x before 1.4.4 allows
remote attackers to cause a denial of service via unknown vectors related to “symbolized
arbitrary strings.”

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

0.013 Low

EPSS

Percentile

85.8%