rubyonrails rails CVE-2021-22904 is a vulnerability in Ruby on Rails Rails
Published on June 11, 2021

The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication logic in Action Controller due to a too permissive regular expression. Impacted code uses `authenticate_or_request_with_http_token` or `authenticate_with_http_token` for request authentication.

NVD

Weakness Type

What is a Resource Exhaustion Vulnerability?

The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

CVE-2021-22904 has been classified to as a Resource Exhaustion vulnerability or weakness.


Products Associated with CVE-2021-22904

Want to know whenever a new CVE is published for Ruby on Rails Rails? stack.watch will email you.

 

Exploit Probability

EPSS
8.20%
Percentile
92.06%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.