Rack vulnerable to Denial of Service via large parameter depth request
Moderate severity
GitHub Reviewed
Published
Oct 24, 2017
to the GitHub Advisory Database
•
Updated Aug 28, 2023
Package
Affected versions
>= 1.6.0, < 1.6.2
>= 1.5.0, < 1.5.4
>= 1.4.0, < 1.4.6
Patched versions
1.6.2
1.5.4
1.4.6
Description
Published to the GitHub Advisory Database
Oct 24, 2017
Reviewed
Jun 16, 2020
Last updated
Aug 28, 2023
lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.
References