10
CVSSv3

CVE-2022-30123

Published: 05/12/2022 Updated: 08/12/2023
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rack project rack

debian debian linux 11.0

Vendor Advisories

Synopsis Important: Red Hat Gluster Storage web-admin-build security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat Gluster Storage 35 for RHEL 7Red Hat Product Security ha ...
Synopsis Moderate: Red Hat OpenShift (Logging Subsystem) security update Type/Severity Security Advisory: Moderate Topic An update is now available for the Logging subsystem for Red Hat OpenShift 54Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, ...
Synopsis Important: pcs security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for pcs is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security ...
Several vulnerabilities were discovered in ruby-rack, a modular Ruby webserver interface, which may result in denial of service and shell escape sequence injection For the oldstable distribution (bullseye), these problems have been fixed in version 214-3+deb11u1 We recommend that you upgrade your ruby-rack packages For the detailed security st ...
A denial of service flaw was found in ruby-rack An attacker crafting multipart POST requests can cause Rack's multipart parser to take much longer than expected, leading to a denial of service (CVE-2022-30122) A flaw was found in ruby gem-rack This flaw allows a malicious actor to craft requests that can cause shell escape sequences to be writte ...