VDB
Sign up
MEDIUM6.5

GHSA-p9fm-f462-ggrg

Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests

Quick fix

GHSA-p9fm-f462-ggrg — activestorage: upgrade to the fixed version with the command below.

bundle update activestorage

Details

### Impact Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability.

### Releases The fixed releases are available at the normal locations.

### Credit This issue was responsibly reported by Hackerone researcher [thwin_htet](https://hackerone.com/thwin_htet).

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/activestorage
Introduced in: 8.1.0Fixed in: 8.1.2.1
Fixbundle update activestorage
RubyGems/activestorage
Introduced in: 8.0.0Fixed in: 8.0.4.1
Fixbundle update activestorage
RubyGems/activestorage
Introduced in: 0Fixed in: 7.2.3.1
Fixbundle update activestorage

References