[CVE-2023-27539] Possible Denial of Service Vulnerability in Rack’s header parsing

Disclosed: 2023-08-15 20:20:36 By ooooooo_q To ibb
Medium
Vulnerability Details
I made a report and patch at https://hackerone.com/reports/1887373 . https://discuss.rubyonrails.org/t/cve-2023-27539-possible-denial-of-service-vulnerability-in-racks-header-parsing/82466 > There is a denial of service vulnerability in the header parsing component of Rack. This vulnerability has been assigned the CVE identifier CVE-2023-27539. ## Impact > Carefully crafted input can cause header parsing in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that parse headers using Rack (virtually all Rails applications) are impacted.
Actions
View on HackerOne
Report Stats
  • Report ID: 2071556
  • State: Closed
  • Substate: resolved
  • Upvotes: 5
Share this report