A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing to take longer than expected.
References
Link | Resource |
---|---|
https://discuss.rubyonrails.org/t/cve-2023-27530-possible-dos-vulnerability-in-multipart-mime-parsing/82388 | Patch Vendor Advisory |
https://lists.debian.org/debian-lts-announce/2023/04/msg00017.html | Mailing List Third Party Advisory |
https://security.netapp.com/advisory/ntap-20231208-0015/ | |
https://www.debian.org/security/2023/dsa-5530 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: hackerone
Published: 2023-03-10T00:00:00
Updated: 2023-12-08T22:06:17.311008
Reserved: 2023-03-02T00:00:00
Link: CVE-2023-27530
JSON object: View
NVD Information
Status : Modified
Published: 2023-03-10T22:15:10.497
Modified: 2023-12-08T22:15:07.603
Link: CVE-2023-27530
JSON object: View
Redhat Information
No data.