[CVE-2023-27539] Possible Denial of Service Vulnerability in Rack’s header parsing
Medium
Vulnerability Details
I made a report and patch at https://hackerone.com/reports/1887373 .
https://discuss.rubyonrails.org/t/cve-2023-27539-possible-denial-of-service-vulnerability-in-racks-header-parsing/82466
> There is a denial of service vulnerability in the header parsing component of Rack. This vulnerability has been assigned the CVE identifier CVE-2023-27539.
## Impact
> Carefully crafted input can cause header parsing in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that parse headers using Rack (virtually all Rails applications) are impacted.
Actions
View on HackerOneReport Stats
- Report ID: 2071556
- State: Closed
- Substate: resolved
- Upvotes: 5