rubyonrails rails CVE-2021-22902 is a vulnerability in Ruby on Rails Rails
Published on June 11, 2021

The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic backtracking in the regular expression engine.

NVD

Weakness Type

What is a Resource Exhaustion Vulnerability?

The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

CVE-2021-22902 has been classified to as a Resource Exhaustion vulnerability or weakness.


Products Associated with CVE-2021-22902

Want to know whenever a new CVE is published for Ruby on Rails Rails? stack.watch will email you.

 

Exploit Probability

EPSS
1.06%
Percentile
77.39%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.