VDB
Sign up
MEDIUM

GHSA-47m2-26rw-j2jw

ReDoS Vulnerability in Rack::Multipart handle_mime_head

Quick fix

GHSA-47m2-26rw-j2jw — rack: upgrade to the fixed version with the command below.

bundle update rack

Details

### Summary There is a denial of service vulnerability in the Content-Disposition parsing component of Rack. This is very similar to the previous security issue CVE-2022-44571.

### Details

Carefully crafted input can cause Content-Disposition header parsing in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. This header is used typically used in multipart parsing. Any applications that parse multipart posts using Rack (virtually all Rails applications) are impacted.

### Credits

Thanks to [scyoon](https://hackerone.com/scyoon) for reporting this to the Rails security team

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rack
Introduced in: 3.1.0Fixed in: 3.1.16
Fixbundle update rack

References