CVE-2023-27530
Last modified
CVE-2023-27530 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing to take longer than expected.. EPSS estimates a 1.83% chance of exploitation in the next 30 days.
Description
A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing to take longer than expected.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rack | Rack | < 2.0.9.3 |
| Rack | Rack | >= 2.1.0, < 2.1.4.3 |
| Rack | Rack | >= 2.2.0, < 2.2.6.3 |
| Rack | Rack | >= 3.0.0, < 3.0.4.2 |
| Debian | Debian Linux | 10.0 |
| Debian | Debian Linux | 11.0 |
References
- https://lists.debian.org/debian-lts-announce/2023/04/msg00017.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2023/dsa-5530Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/04/msg00017.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2023/dsa-5530Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-27530?
How severe is CVE-2023-27530?
How do I fix CVE-2023-27530?
Are you affected by CVE-2023-27530?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
