vulnerability

FreeBSD: VID-95176BA5-9796-11ED-BFBF-080027F5FEC9 (CVE-2022-44572): rack -- Multiple vulnerabilities

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Jan 17, 2023
Added
Jan 20, 2023
Modified
Jan 28, 2025

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-95176BA5-9796-11ED-BFBF-080027F5FEC9:




Aaron Patterson reports:




CVE-2022-44570



Carefully crafted input can cause the Range header


parsing component in Rack to take an unexpected amount


of time, possibly resulting in a denial of service


attack vector. Any applications that deal with Range


requests (such as streaming applications, or


applications that serve files) may be impacted.



CVE-2022-44571



Carefully crafted input can cause Content-Disposition


header parsing in Rack to take an unexpected amount of


time, possibly resulting in a denial of service attack


vector. This header is used typically used in multipart


parsing. Any applications that parse multipart posts


using Rack (virtually all Rails applications) are


impacted.



CVE-2022-44572



Carefully crafted input can cause RFC2183 multipart


boundary parsing in Rack to take an unexpected amount of


time, possibly resulting in a denial of service attack


vector. Any applications that parse multipart posts


using Rack (virtually all Rails applications) are


impacted.






Solution(s)

freebsd-upgrade-package-rubygem-rackfreebsd-upgrade-package-rubygem-rack16freebsd-upgrade-package-rubygem-rack22
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.