Miggo Logo

CVE-2022-44571: Denial of Service Vulnerability in Rack Content-Disposition parsing

7.5

CVSS Score
3.1

Basic Information

EPSS Score
0.84251%
Published
1/18/2023
Updated
10/23/2023
KEV Status
No
Technology
TechnologyRuby

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
rackrubygems>= 2.0.0, < 2.0.9.22.0.9.2
rackrubygems>= 2.1.0, < 2.1.4.22.1.4.2
rackrubygems>= 2.2.0, < 2.2.6.12.2.6.1
rackrubygems>= 3.0.0.0, < 3.0.4.13.0.4.1

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

T**r* is * **ni*l o* s*rvi** vuln*r**ility in t** *ont*nt-*isposition p*rsin* *ompon*nt o* R**k. T*is vuln*r**ility **s ***n *ssi*n** t** *V* i**nti*i*r *V*-****-*****. V*rsions *****t**: >= *.*.* Not *****t**: Non*. *ix** V*rsions: *.*.*.*, *.*.*.*

Reasoning

No *n*lysis *v*il**l*