cbcvebase.

Debian Ruby-Rack vulnerabilities

48 known vulnerabilities affecting debian/ruby-rack.

Total CVEs
48
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH18MEDIUM27LOW2

Vulnerabilities

Page 3 of 3
CVE-2013-0262P4MEDIUMCVSS 4.3fixed in ruby-rack 1.4.1-2.1 (bookworm)2013
CVE-2013-0262 [MEDIUM] CVE-2013-0262: ruby-rack - rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allo... rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO environment variable, probably a directory traversal vulnerability that is remotely exploitable, aka "symlink path traversals." Scope: local bookworm: resolved (fixed in 1.4.1-2.1) bullse
debian
CVE-2025-49007P4LOWCVSS 7.5fixed in ruby-rack 3.1.16-0.1 (forky)2025
CVE-2025-49007 [HIGH] CVE-2025-49007: ruby-rack - Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior... Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.16, there is a denial of service vulnerability in the Content-Disposition parsing component of Rack. This is very similar to the previous security issue CVE-2022-44571. Carefully crafted input can cause Content-Disposition header parsing in Rack to take an unexpected am
debian
CVE-2023-27539P4MEDIUMCVSS 5.3fixed in ruby-rack 2.2.6.4-1 (bookworm)2023
CVE-2023-27539 [MEDIUM] CVE-2023-27539: ruby-rack - There is a denial of service vulnerability in the header parsing component of Ra... There is a denial of service vulnerability in the header parsing component of Rack. Scope: local bookworm: resolved (fixed in 2.2.6.4-1) bullseye: resolved (fixed in 2.1.4-3+deb11u1) forky: resolved (fixed in 2.2.6.4-1) sid: resolved (fixed in 2.2.6.4-1) trixie: resolved (fixed in 2.2.6.4-1)
debian
CVE-2011-5036P4MEDIUMCVSS 5.0fixed in ruby-rack 1.4.0-1 (bookworm)2011
CVE-2011-5036 [MEDIUM] CVE-2011-5036: ruby-rack - Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash valu... Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. Scope: local bookworm: resolved (fixed in 1.4.0-1) bullseye: resolved (fixed i
debian
CVE-2013-0183P4MEDIUMCVSS 5.0fixed in ruby-rack 1.4.1-2.1 (bookworm)2013
CVE-2013-0183 [MEDIUM] CVE-2013-0183: ruby-rack - multipart/parser.rb in Rack 1.3.x before 1.3.8 and 1.4.x before 1.4.3 allows rem... multipart/parser.rb in Rack 1.3.x before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a long string in a Multipart HTTP packet. Scope: local bookworm: resolved (fixed in 1.4.1-2.1) bullseye: resolved (fixed in 1.4.1-2.1) forky: resolved (fixed in 1.4.1-2.1) sid: resolved (fixed i
debian
CVE-2013-0184P4MEDIUMCVSS 4.3fixed in ruby-rack 1.4.1-2.1 (bookworm)2013
CVE-2013-0184 [MEDIUM] CVE-2013-0184: ruby-rack - Unspecified vulnerability in Rack::Auth::AbstractRequest in Rack 1.1.x before 1.... Unspecified vulnerability in Rack::Auth::AbstractRequest in Rack 1.1.x before 1.1.5, 1.2.x before 1.2.7, 1.3.x before 1.3.9, and 1.4.x before 1.4.4 allows remote attackers to cause a denial of service via unknown vectors related to "symbolized arbitrary strings." Scope: local bookworm: resolved (fixed in 1.4.1-2.1) bullseye: resolved (fixed in 1.4.1-2.1) forky: re
debian
CVE-2025-32441P4MEDIUMCVSS 4.2fixed in ruby-rack 2.2.20-0+deb12u1 (bookworm)2025
CVE-2025-32441 [MEDIUM] CVE-2025-32441: ruby-rack - Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using... Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy that session. Rack session middleware prepares the session at the beginning of request, then saves is back to the store with possible
debian
CVE-2012-6109P4MEDIUMCVSS 4.3fixed in ruby-rack 1.4.1-2.1 (bookworm)2012
CVE-2012-6109 [MEDIUM] CVE-2012-6109: ruby-rack - lib/rack/multipart.rb in Rack before 1.1.4, 1.2.x before 1.2.6, 1.3.x before 1.3... lib/rack/multipart.rb in Rack before 1.1.4, 1.2.x before 1.2.6, 1.3.x before 1.3.7, and 1.4.x before 1.4.2 uses an incorrect regular expression, which allows remote attackers to cause a denial of service (infinite loop) via a crafted Content-Disposion header. Scope: local bookworm: resolved (fixed in 1.4.1-2.1) bullseye: resolved (fixed in 1.4.1-2.1) forky: resolv
debian
Debian Ruby-Rack vulnerabilities | cvebase