PT-2023-2035 · Rack+9 · Rack+9

Das7Pad

·

Publicado

2023-03-08

·

Atualizado

2026-03-13

·

CVE-2023-27530

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Rack versions prior to 3.0.4.2 Rack versions prior to 2.2.6.3 Rack versions prior to 2.1.4.3 Rack versions prior to 2.0.9.3
Description A DoS issue exists in the Multipart MIME parsing code, allowing an attacker to craft requests that can be abused to cause multipart parsing to take longer than expected. This could lead to an exploitation that allows a remote attacker to cause a denial of service. The Multipart MIME parsing code limits the number of file parts but does not limit the total number of parts that can be uploaded, which can be exploited by carefully crafted requests.
Recommendations For versions prior to 3.0.4.2, update to version 3.0.4.2 or later. For versions prior to 2.2.6.3, update to version 2.2.6.3 or later. For versions prior to 2.1.4.3, update to version 2.1.4.3 or later. For versions prior to 2.0.9.3, update to version 2.0.9.3 or later. As a temporary workaround, consider configuring a proxy to limit the POST body size to mitigate this issue.

Exploit

Correção

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2023:2652
ALSA-2023:3082
ALSA-2023_2652
ALSA-2023_3082
BDU:2023-01752
CESA-2023_3082
CVE-2023-27530
DLA-3392-1
DSA-5530-1
GHSA-3H57-HMJ3-GJ3P
MGASA-2023-0106
OPENSUSE-SU-2024:12773-1
OPENSUSE-SU-2024:12784-1
OPENSUSE-SU-2024:12886-1
OPENSUSE-SU-2024:13726-1
OPENSUSE-SU-2024:13727-1
OPENSUSE-SU-2025:14811-1
OPENSUSE-SU-2025:14875-1
OPENSUSE-SU-2026:10286-1
OPENSUSE-SU-2026:10358-1
RHSA-2023:1961
RHSA-2023:1981
RHSA-2023:2652
RHSA-2023:3082
RHSA-2023:3403
RHSA-2023:6818
RHSA-2023_2652
RHSA-2023_3082
RLSA-2023:2652
RLSA-2023:3082
RLSA-2023:6818
SUSE-SU-2023:0725-1
SUSE-SU-2023:2280-1
SUSE-SU-2023:2294-1
SUSE-SU-2023:2295-1
SUSE-SU-2023:2304-1
SUSE-SU-2023:2781-1
SUSE-SU-2023_0725-1
SUSE-SU-2023_2280-1
SUSE-SU-2023_2294-1
SUSE-SU-2023_2295-1
SUSE-SU-2023_2304-1
USN-6837-1
USN-6905-1
USN-7036-1

Produtos afetados

Almalinux
Astra Linux
Centos
Linuxmint
Rack
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu