Description
The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic backtracking in the regular expression engine.
Related CPE's
a
rubyonrails
rails
2
References
ExploitMitigationPatchVendor Advisory
https://hackerone.com/reports/1138654
Permissions RequiredThird Party Advisory
ExploitMitigationPatchVendor Advisory
https://hackerone.com/reports/1138654
Permissions RequiredThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
7.5 · High
Information
Source identifier
Vulnerability status
Modified
Published
2021-06-11T14:15:11.360Z
4 years agoLast modified
2024-11-21T04:50:52.777Z
1 year ago