VDB
CVE-2021-22902
CVE-2021-22902
PUBLISHED
The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic backtracking in the regular expression engine.
EPSS 0.68% · 72.0th percentile
Risk Scores
EPSS Score
0.68%
72.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:25.10 | rails | 2:7.2.2.1+dfsg-7, 2:6.1.7.3+dfsg-7, 0 |
| Ubuntu:24.04:LTS | rails | 2:6.1.7.3+dfsg-2build1, 2:6.1.7.3+dfsg-3, 0 |
| Ubuntu:Pro:20.04:LTS | rails | 0, 2:5.2.2.1+dfsg-1ubuntu1, 2:5.2.3+dfsg-3 |
| Ubuntu:Pro:16.04:LTS | rails | 2:4.2.5.1-1, 2:4.2.5-1, 2:4.2.5.2-2 |
| Ubuntu:Pro:22.04:LTS | rails | 0, 2:6.1.4.1+dfsg-8ubuntu2+esm1, 2:6.1.4.1+dfsg-8ubuntu2 |
| Ubuntu:Pro:18.04:LTS | rails | *, *, * |
Exploit Intelligence
- https://discuss.rubyonrails.org/t/cve-2021-22902-possible-denial-of-service-vulnerability-in-action-dispatch/77866 (nist-nvd)
- https://hackerone.com/reports/1138654 (nist-nvd)
- .bundler-audit.yml (github-poc)
- .bundler-audit.yml (github-poc)
- .bundler-audit.yml (github-poc)
- .bundler-audit.yml (github-poc)
- .bundler-audit.yml (github-poc)
- .bundler-audit.yml (github-poc)
- .bundler-audit.yml (github-poc)
- .bundler-audit.yml (github-poc)
…and 97 more exploits
Timeline
- May 5, 2021 CVE Published
- Jun 12, 2021 EPSS Score
- Aug 13, 2021 EPSS Score
- Dec 12, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 13, 2022 EPSS Score
- Jun 12, 2022 EPSS Score
- Aug 13, 2022 EPSS Score
- Dec 8, 2022 CVE Updated
- Dec 13, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2021-22902 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2021-22902 third-party-advisory