VDB
Sign up
MEDIUM

GHSA-rgr4-9jh5-j4j6

Rack vulnerable to Denial of Service via large parameter depth request

Quick fix

GHSA-rgr4-9jh5-j4j6 — rack: upgrade to the fixed version with the command below.

bundle update rack

Details

lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rack
Introduced in: 1.5.0Fixed in: 1.5.4
Fixbundle update rack
RubyGems/rack
Introduced in: 1.6.0Fixed in: 1.6.2
Fixbundle update rack
RubyGems/rack
Introduced in: 1.4.0Fixed in: 1.4.6
Fixbundle update rack

References