USN-5896-1
Dashboard / Vulnerabilities / USN-5896-1
USN-5896-1
Summary: ruby-rack vulnerabilities
Details: It was discovered that Rack was not properly parsing data when processing multipart POST requests. If a user or automated system were tricked into sending a specially crafted multipart POST request to an application using Rack, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2022-30122) It was discovered that Rack was not properly escaping untrusted data when performing logging operations, which could cause shell escaped sequences to be written to a terminal. If a user or automated system were tricked into sending a specially crafted request to an application using Rack, a remote attacker could possibly use this issue to execute arbitrary code in the machine running the application. (CVE-2022-30123)
References: https://ubuntu.com/security/notices/USN-5896-1, https://ubuntu.com/security/CVE-2022-30122, https://ubuntu.com/security/CVE-2022-30123
Affected packages
Package
Name: ruby-rack
Purl: pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-apps/bionic
Affected ranges
Type: ECOSYSTEM
Events:
