PT-2023-2035 · Rack+9 · Rack+9

Das7Pad

·

Published

2023-03-08

·

Updated

2026-03-13

·

CVE-2023-27530

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Rack versions prior to 3.0.4.2 Rack versions prior to 2.2.6.3 Rack versions prior to 2.1.4.3 Rack versions prior to 2.0.9.3
Description A DoS issue exists in the Multipart MIME parsing code, allowing an attacker to craft requests that can be abused to cause multipart parsing to take longer than expected. This could lead to an exploitation that allows a remote attacker to cause a denial of service. The Multipart MIME parsing code limits the number of file parts but does not limit the total number of parts that can be uploaded, which can be exploited by carefully crafted requests.
Recommendations For versions prior to 3.0.4.2, update to version 3.0.4.2 or later. For versions prior to 2.2.6.3, update to version 2.2.6.3 or later. For versions prior to 2.1.4.3, update to version 2.1.4.3 or later. For versions prior to 2.0.9.3, update to version 2.0.9.3 or later. As a temporary workaround, consider configuring a proxy to limit the POST body size to mitigate this issue.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:2652
ALSA-2023:3082
ALSA-2023_2652
ALSA-2023_3082
BDU:2023-01752
CESA-2023_3082
CVE-2023-27530
DLA-3392-1
DSA-5530-1
GHSA-3H57-HMJ3-GJ3P
MGASA-2023-0106
OPENSUSE-SU-2024:12773-1
OPENSUSE-SU-2024:12784-1
OPENSUSE-SU-2024:12886-1
OPENSUSE-SU-2024:13726-1
OPENSUSE-SU-2024:13727-1
OPENSUSE-SU-2025:14811-1
OPENSUSE-SU-2025:14875-1
OPENSUSE-SU-2026:10286-1
OPENSUSE-SU-2026:10358-1
RHSA-2023:1961
RHSA-2023:1981
RHSA-2023:2652
RHSA-2023:3082
RHSA-2023:3403
RHSA-2023:6818
RHSA-2023_2652
RHSA-2023_3082
RLSA-2023:2652
RLSA-2023:3082
RLSA-2023:6818
SUSE-SU-2023:0725-1
SUSE-SU-2023:2280-1
SUSE-SU-2023:2294-1
SUSE-SU-2023:2295-1
SUSE-SU-2023:2304-1
SUSE-SU-2023:2781-1
SUSE-SU-2023_0725-1
SUSE-SU-2023_2280-1
SUSE-SU-2023_2294-1
SUSE-SU-2023_2295-1
SUSE-SU-2023_2304-1
USN-6837-1
USN-6905-1
USN-7036-1

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Rack
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu