CVE-2022-44572

HIGH

Rack < 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1 - Denial of Service via Multipart Boundary Parsing

Title source: llm
STIX 2.1

Description

A denial of service vulnerability in the multipart parsing component of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1 and 3.0.0.1 could allow an attacker tocraft input that can cause RFC2183 multipart boundary parsing in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that parse multipart posts using Rack (virtually all Rails applications) are impacted.

References (3)

Core 3
Core References
Permissions Required, Third Party Advisory
https://hackerone.com/reports/1639882
Third Party Advisory vendor-advisory
https://www.debian.org/security/2023/dsa-5530

Scores

CVSS v3 7.5
EPSS 0.0162
EPSS Percentile 72.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-1333 CWE-400
Status published
Products (2)
rack/rack < 2.0.9.2
rubygems/rack 2.0.0 - 2.0.9.2RubyGems
Published Feb 09, 2023
Tracked Since Feb 18, 2026