CVE-2022-44572
Summary
| CVE | CVE-2022-44572 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-09 20:15:00 UTC |
| Updated | 2023-12-08 22:15:00 UTC |
| Description | A denial of service vulnerability in the multipart parsing component of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1 and 3.0.0.1 could allow an attacker tocraft input that can cause RFC2183 multipart boundary parsing in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that parse multipart posts using Rack (virtually all Rails applications) are impacted. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Rack Project |
Rack |
All |
All |
All |
All |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181526 Debian Security Update for ruby-rack (DLA 3298-1)
- 182441 Debian Security Update for ruby-rack (CVE-2022-44572)
- 199546 Ubuntu Security Notification for Rack Vulnerabilities (USN-5910-1)
- 242347 Red Hat Update for Satellite 6.14 (RHSA-2023:6818)
- 6000290 Debian Security Update for ruby-rack (DSA 5530-1)
- 691031 Free Berkeley Software Distribution (FreeBSD) Security Update for rack (95176ba5-9796-11ed-bfbf-080027f5fec9)
- 753622 SUSE Enterprise Linux Security Update for rubygem-rack (SUSE-SU-2023:0276-1)
- 961065 Rocky Linux Security Update for Satellite (RLSA-2023:6818)