CVE-2021-22904 is a denial-of-service vulnerability affecting the Action Pack Ruby gem in Ruby on Rails versions prior to 6.1.3.2, 6.0.3.7, 5.2.4.6, and 5.2.6. This flaw stems from an overly permissive regular expression used in the Token Authentication logic, specifically when applications utilize authenticate_or_request_with_http_token or authenticate_with_http_token. With a CVSS score of 7.5 (High), this vulnerability can be exploited remotely with low attack complexity, leading to a complete denial of service without requiring user interaction or privileges. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.2.4.6CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* | ||
>= 5.2.5, < 5.2.6CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.0.3.7CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* | ||
>= 6.1.0, < 6.1.3.2CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.