VDB
Sign up
HIGH7.5

GHSA-hxqx-xwvh-44m2

Denial of Service Vulnerability in Rack Multipart Parsing

Quick fix

GHSA-hxqx-xwvh-44m2 — rack: upgrade to the fixed version with the command below.

bundle update rack

Details

There is a possible denial of service vulnerability in the multipart parsing component of Rack. This vulnerability has been assigned the CVE identifier CVE-2022-30122.

Versions Affected: >= 1.2 Not affected: < 1.2 Fixed Versions: 2.0.9.1, 2.1.4.1, 2.2.3.1

## Impact Carefully crafted multipart POST requests can cause Rack's multipart parser to take much longer than expected, leading to a possible denial of service vulnerability.

Impacted code will use Rack's multipart parser to parse multipart posts. This includes directly using the multipart parser like this:

``` params = Rack::Multipart.parse_multipart(env) ```

But it also includes reading POST data from a Rack request object like this:

``` p request.POST # read POST data p request.params # reads both query params and POST data ```

All users running an affected release should either upgrade or use one of the workarounds immediately.

## Workarounds There are no feasible workarounds for this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rack
Introduced in: 1.2Fixed in: 2.0.9.1
Fixbundle update rack
RubyGems/rack
Introduced in: 2.1Fixed in: 2.1.4.1
Fixbundle update rack
RubyGems/rack
Introduced in: 2.2Fixed in: 2.2.3.1
Fixbundle update rack

References