Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39000
HistoryJan 25, 2023 - 2:40 a.m.

Regular Expression Denial Of Service(ReDoS)

2023-01-2502:40:54
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
vulnerability
rack
redos
multipart.rb
handle_mime_head
inefficient regular expression

0.001 Low

EPSS

Percentile

41.6%

rack is vulnerable to Regular Expression Denial of Service(ReDoS). The vulnerability exists in the handle_mime_head function of multipart.rb due to inefficient regular expression complexity which allows an attacker to crash the application by submitting a malicious input with the Content-Disposition header.