VDB
CVE-2021-22902
CVE-2021-22902
PUBLISHED
CVSS 7.5 HIGH
The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic backtracking in the regular expression engine.
EPSS 2.79% · 85.8th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
2.79%
85.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:25.10 | rails | 2:7.2.2.1+dfsg-7, 2:6.1.7.3+dfsg-7, 0 |
| Ubuntu:24.04:LTS | rails | 2:6.1.7.3+dfsg-2build1, 2:6.1.7.3+dfsg-3, 0 |
| Ubuntu:Pro:20.04:LTS | rails | 0, 2:5.2.2.1+dfsg-1ubuntu1, 2:5.2.3+dfsg-3 |
| Ubuntu:Pro:16.04:LTS | rails | 2:4.2.5.1-1, 2:4.2.5-1, 2:4.2.5.2-2 |
| Ubuntu:Pro:22.04:LTS | rails | 0, 2:6.1.4.1+dfsg-8ubuntu2+esm1, 2:6.1.4.1+dfsg-8ubuntu2 |
| Ubuntu:Pro:18.04:LTS | rails | *, *, * |
Timeline
- May 5, 2021 CVE Published
- Jun 12, 2021 EPSS Score
- Aug 13, 2021 EPSS Score
- Dec 13, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 14, 2022 EPSS Score
- Jun 14, 2022 EPSS Score
- Oct 14, 2022 EPSS Score
- Dec 8, 2022 CVE Updated
- Dec 14, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2021-22902 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2021-22902 third-party-advisory