Rack Project

Rack

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.92%
  • Veröffentlicht 05.12.2022 22:15:10
  • Zuletzt bearbeitet 21.11.2024 07:02:12

A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack.

  • EPSS 2.26%
  • Veröffentlicht 05.12.2022 22:15:10
  • Zuletzt bearbeitet 21.11.2024 07:02:12

A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.

  • EPSS 0.48%
  • Veröffentlicht 02.07.2020 19:15:12
  • Zuletzt bearbeitet 21.11.2024 05:38:24

A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.

Exploit
  • EPSS 1.07%
  • Veröffentlicht 19.06.2020 17:15:18
  • Zuletzt bearbeitet 21.11.2024 05:38:27

A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.

  • EPSS 0.18%
  • Veröffentlicht 13.11.2018 23:29:00
  • Zuletzt bearbeitet 21.11.2024 03:52:49

There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate to the request size.

  • EPSS 0.17%
  • Veröffentlicht 13.11.2018 23:29:00
  • Zuletzt bearbeitet 21.11.2024 03:52:49

There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do no...

  • EPSS 14.08%
  • Veröffentlicht 26.07.2015 22:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.

  • EPSS 1.82%
  • Veröffentlicht 01.03.2013 05:40:17
  • Zuletzt bearbeitet 11.04.2025 00:51:21

multipart/parser.rb in Rack 1.3.x before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a long string in a Multipart HTTP packet.

  • EPSS 0.68%
  • Veröffentlicht 01.03.2013 05:40:17
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Unspecified vulnerability in Rack::Auth::AbstractRequest in Rack 1.1.x before 1.1.5, 1.2.x before 1.2.7, 1.3.x before 1.3.9, and 1.4.x before 1.4.4 allows remote attackers to cause a denial of service via unknown vectors related to "symbolized arbitr...

  • EPSS 0.83%
  • Veröffentlicht 01.03.2013 05:40:16
  • Zuletzt bearbeitet 11.04.2025 00:51:21

lib/rack/multipart.rb in Rack before 1.1.4, 1.2.x before 1.2.6, 1.3.x before 1.3.7, and 1.4.x before 1.4.2 uses an incorrect regular expression, which allows remote attackers to cause a denial of service (infinite loop) via a crafted Content-Disposio...