CVE-2022-44571 is a denial-of-service vulnerability in the Content-Disposition parsing component of Rack, affecting versions prior to 2.0.9.2, 2.1.4.2, 2.2.4.1, and 3.0.0.1. An unauthenticated attacker can craft a malicious Content-Disposition header in a multipart post, causing Rack to consume excessive processing time. This can lead to a denial-of-service against applications, including virtually all Rails applications, that parse multipart posts using Rack. The vulnerability has a CVSS score of 7.5 (HIGH) due to its network attack vector and low attack complexity, with a high impact on availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.0.9.2CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* | ||
>= 2.1.0, < 2.1.4.2CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* | ||
>= 2.2.0, < 2.2.6.1CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* | ||
>= 3.0.0.0, < 3.0.4.1CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.