Asymmetric denial of service In rails
Description
There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 2:5.2.2.1+dfsg-1 | ||
rubygems | 4.2.11.1, 5.2.2.1, 5.1.6.2, 5.0.7.2, 6.0.0.beta3 | ||
debian 14 | 2:5.2.2.1+dfsg-1 | ||
debian 13 | 2:5.2.2.1+dfsg-1 | ||
rubygems | 4.2.11.1, 5.0.7.2, 5.1.6.2, 5.2.2.1 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.