CVE-2021-22902
Denial of Service in Action Dispatch
7.5
HIGH
CVSS 3.1
EPSS 2.8%
描述
The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic backtracking in the regular expression engine.
如何修補 CVE-2021-22902
要修補 CVE-2021-22902,請將受影響套件升級到下列已修補版本。
- —升級至 2:6.0.3.7+dfsg-1 或更新版本
- —升級至 6.0.3.7 或更新版本
CVE-2021-22902 正在被利用嗎?
低 — EPSS 為 2.8%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 2:6.0.3.7+dfsg-1
- >= 6.0.0, < 6.0.3.7
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |