CVE Database
/

CVE-2022-44571

Back to search

CVE-2022-44571

Published: Feb 9, 2023

Modified: Aug 3, 2024

PUBLISHED

Description

There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1. This could allow an attacker to craft an input that can cause Content-Disposition header parsing in Rackto take an unexpected amount of time, possibly resulting in a denial ofservice attack vector. This header is used typically used in multipartparsing. Any applications that parse multipart posts using Rack (virtuallyall Rails applications) are impacted.

VendorProductVersions

n/a

https://github.com/rack/rack

affected
2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now