VDB
Sign up
MEDIUM

GHSA-r46p-8f7g-vvvg

Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests

Quick fix

GHSA-r46p-8f7g-vvvg — activestorage: upgrade to the fixed version with the command below.

bundle update activestorage

Details

### Impact When serving files through Active Storage's `Blobs::ProxyController`, the controller loads the entire requested byte range into memory before sending it. A request with a large or unbounded Range header (e.g. `bytes=0-`) could cause the server to allocate memory proportional to the file size, possibly resulting in a DoS vulnerability through memory exhaustion.

### Releases The fixed releases are available at the normal locations.

### Credit This issue was responsibly reported by Hackerone user [pirikara](https://hackerone.com/pirikara)

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/activestorage
Introduced in: 8.1.0.beta1Fixed in: 8.1.2.1
Fixbundle update activestorage
RubyGems/activestorage
Introduced in: 8.0.0.beta1Fixed in: 8.0.4.1
Fixbundle update activestorage
RubyGems/activestorage
Introduced in: 0Fixed in: 7.2.3.1
Fixbundle update activestorage

References