GHSA-hxqx-xwvh-44m2

    Dashboard / Vulnerabilities / GHSA-hxqx-xwvh-44m2

    GHSA-hxqx-xwvh-44m2

    Published: 27 May 2022Last Modified: 18 Feb 2024

    Summary: Denial of Service Vulnerability in Rack Multipart Parsing

    Details: There is a possible denial of service vulnerability in the multipart parsing component of Rack. This vulnerability has been assigned the CVE identifier CVE-2022-30122. Versions Affected: >= 1.2 Not affected: < 1.2 Fixed Versions: 2.0.9.1, 2.1.4.1, 2.2.3.1 ## Impact Carefully crafted multipart POST requests can cause Rack's multipart parser to take much longer than expected, leading to a possible denial of service vulnerability. Impacted code will use Rack's multipart parser to parse multipart posts. This includes directly using the multipart parser like this: ``` params = Rack::Multipart.parse_multipart(env) ``` But it also includes reading POST data from a Rack request object like this: ``` p request.POST # read POST data p request.params # reads both query params and POST data ``` All users running an affected release should either upgrade or use one of the workarounds immediately. ## Workarounds There are no feasible workarounds for this issue.

    Affected packages

    Package

    Name: rack

    Purl: pkg:gem/rack

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 1.2
    Fixed -2.0.9.1

    Affected versions

    1.2.0
    1.2.1
    1.2.2
    1.2.3
    1.2.4
    1.2.5
    1.2.6
    1.2.7
    1.2.8

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-hxqx-xwvh-44m2 | CVE-DB