Skip to main content

Vendor/product archive

rack_project / rack CVEs

Beta · best-effort

13 CVEs tagged to rack_project / rack1 Critical, 4 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2022-30123

Published Dec 5, 2022

A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-16471

Published Nov 13, 2018

There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applicati…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16470

Published Nov 13, 2018

There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-0184

Published Mar 1, 2013

Unspecified vulnerability in Rack::Auth::AbstractRequest in Rack 1.1.x before 1.1.5, 1.2.x before 1.2.7, 1.3.x before 1.3.9, and 1.4.x before 1.4.4 allows remote attackers to caus…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0183

Published Mar 1, 2013

multipart/parser.rb in Rack 1.3.x before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a long…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6109

Published Mar 1, 2013

lib/rack/multipart.rb in Rack before 1.1.4, 1.2.x before 1.2.6, 1.3.x before 1.3.7, and 1.4.x before 1.4.2 uses an incorrect regular expression, which allows remote attackers to c…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0263

Published Feb 8, 2013

Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0262

Published Feb 8, 2013

rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5036

Published Dec 30, 2011

Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, whic…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1