The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic backtracking in the regular expression engine.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-1076 The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic backtracking in the regular expression engine.
Github GHSA Github GHSA GHSA-g8ww-46x2-2p65 Denial of Service in Action Dispatch
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2024-08-03T18:58:25.713Z

Reserved: 2021-01-06T00:00:00

Link: CVE-2021-22902

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-06-11T16:15:11.360

Modified: 2024-11-21T05:50:52.777

Link: CVE-2021-22902

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-05-05T00:00:00Z

Links: CVE-2021-22902 - Bugzilla

cve-icon OpenCVE Enrichment

No data.