CVE-2021-22904

Related Vulnerabilities: CVE-2021-22904  

A flaw was found in RubyGem Actionpack which is framework for handling and responding to web requests in Rails. A possible DoS vulnerability was found in the Token Authentication logic in Action Controller.

Description

A flaw was found in RubyGem Actionpack which is framework for handling and responding to web requests in Rails. A possible DoS vulnerability was found in the Token Authentication logic in Action Controller.

Statement

Red Hat CloudForms 5.0 (CFME 5.11) is in the maintenance phase and we will not be fixing Medium/Low impact security bugs. Reference: https://access.redhat.com/support/policy/updates/cloudforms

Red Hat CloudForms 5.0 (CFME 5.11) is in the maintenance phase and we will not be fixing Medium/Low impact security bugs. Reference: https://access.redhat.com/support/policy/updates/cloudforms

Additional Information

  • Bugzilla 1961379: CVE-2021-22904 rails: Possible DoS Vulnerability in Action Controller Token Authentication
  • CWE-400: Uncontrolled Resource Consumption
  • FAQ: Frequently asked questions about CVE-2021-22904