VDB

CVE-2021-22902

CVE-2021-22902 PUBLISHED CVSS 7.5 HIGH

The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic backtracking in the regular expression engine.

EPSS 2.79% · 85.8th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
2.79%
85.8th percentile

Affected Products

VendorProductVersions
Ubuntu:25.10rails2:7.2.2.1+dfsg-7, 2:6.1.7.3+dfsg-7, 0
Ubuntu:24.04:LTSrails2:6.1.7.3+dfsg-2build1, 2:6.1.7.3+dfsg-3, 0
Ubuntu:Pro:20.04:LTSrails0, 2:5.2.2.1+dfsg-1ubuntu1, 2:5.2.3+dfsg-3
Ubuntu:Pro:16.04:LTSrails2:4.2.5.1-1, 2:4.2.5-1, 2:4.2.5.2-2
Ubuntu:Pro:22.04:LTSrails0, 2:6.1.4.1+dfsg-8ubuntu2+esm1, 2:6.1.4.1+dfsg-8ubuntu2
Ubuntu:Pro:18.04:LTSrails*, *, *

Timeline

  • May 5, 2021 CVE Published
  • Jun 12, 2021 EPSS Score
  • Aug 13, 2021 EPSS Score
  • Dec 13, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 14, 2022 EPSS Score
  • Jun 14, 2022 EPSS Score
  • Oct 14, 2022 EPSS Score
  • Dec 8, 2022 CVE Updated
  • Dec 14, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›