FlawAtlas
Search the atlas
UBUNTU-CVE-2023-27530 High

UBUNTU-CVE-2023-27530

A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing to take longer than expected.

Exploit probability Not scored
Published March 10, 2023
Required by Not available
Last source change April 17, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:22.04:LTS ruby-rack

4 explicit affected versions

Ubuntu:Pro:14.04:LTS ruby-rack

11 explicit affected versions

Ubuntu:Pro:16.04:LTS ruby-rack

14 explicit affected versions

Ubuntu:Pro:18.04:LTS ruby-rack

12 explicit affected versions

Ubuntu:Pro:20.04:LTS ruby-rack

6 explicit affected versions

Ubuntu:Pro:22.04:LTS ruby-rack

6 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2023-27530

A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing to take longer than expected.

View original source

05 / REFERENCES

Further evidence