NA

CVE-2022-30122

Published: 05/12/2022 Updated: 20/12/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rack project rack

debian debian linux 11.0

Vendor Advisories

Synopsis Important: Red Hat Gluster Storage web-admin-build security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat Gluster Storage 35 for RHEL 7Red Hat Product Security ha ...
Synopsis Important: Satellite 6114 Async Security Update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Updated Satellite 611 packages that fix several bugs are now available for Red Hat Satellite Description Red H ...
Several vulnerabilities were discovered in ruby-rack, a modular Ruby webserver interface, which may result in denial of service and shell escape sequence injection For the oldstable distribution (bullseye), these problems have been fixed in version 214-3+deb11u1 We recommend that you upgrade your ruby-rack packages For the detailed security st ...
A denial of service flaw was found in ruby-rack An attacker crafting multipart POST requests can cause Rack's multipart parser to take much longer than expected, leading to a denial of service (CVE-2022-30122) A flaw was found in ruby gem-rack This flaw allows a malicious actor to craft requests that can cause shell escape sequences to be writte ...