Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). This vulnerability is patched in 3.0.9.1 and 2.2.8.1.
| Software | From | Fixed in |
|---|---|---|
rack
|
3.0.0 | 3.0.9.1 |
rack
|
0.4 | 2.2.8.1 |
| rack / rack | 3.0.0 | 3.0.9.1 |
| rack / rack | 0.4 | 2.2.8.1 |
| debian / debian_linux | 10.0 | 10.0.x |