Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35745
HistoryMay 30, 2022 - 2:27 a.m.

Regular Expression Denial Of Service (ReDoS)

2022-05-3002:27:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.001 Low

EPSS

Percentile

46.4%

rack is vulnerable to regular expression denial of service. The vulnerability exists because the BROKEN_QUOTED and BROKEN_UNQUOTED attributes in the Multipart module of multipart.rb does not properly restrict the broken mime parser, allowing an attacker to crash the application by providing malicious multipart POST requests