Lucene search

K
ubuntuUbuntuUSN-5896-1
HistoryFeb 27, 2023 - 12:00 a.m.

Rack vulnerabilities

2023-02-2700:00:00
ubuntu.com
58
rack
ubuntu
denial of service
arbitrary code execution
cve-2022-30122
cve-2022-30123
multipart post requests
logging operations
ruby

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

75.5%

Releases

  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 ESM

Packages

  • ruby-rack - modular Ruby webserver interface

Details

It was discovered that Rack was not properly parsing data when processing
multipart POST requests. If a user or automated system were tricked into
sending a specially crafted multipart POST request to an application using
Rack, a remote attacker could possibly use this issue to cause a denial of
service. (CVE-2022-30122)

It was discovered that Rack was not properly escaping untrusted data when
performing logging operations, which could cause shell escaped sequences
to be written to a terminal. If a user or automated system were tricked
into sending a specially crafted request to an application using Rack, a
remote attacker could possibly use this issue to execute arbitrary code in
the machine running the application. (CVE-2022-30123)

OSVersionArchitecturePackageVersionFilename
Ubuntu22.04noarchruby-rack< 2.1.4-5ubuntu1+esm2UNKNOWN
Ubuntu22.04noarchruby-rack< 2.1.4-5ubuntu1UNKNOWN
Ubuntu20.04noarchruby-rack< 2.0.7-2ubuntu0.1+esm2UNKNOWN
Ubuntu20.04noarchruby-rack< 2.0.7-2ubuntu0.1UNKNOWN
Ubuntu18.04noarchruby-rack< 1.6.4-4ubuntu0.2+esm2UNKNOWN
Ubuntu18.04noarchruby-rack< 1.6.4-4ubuntu0.2UNKNOWN

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

75.5%