Risk Scores
CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.83%
74.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| RubyGems | rack | 3.1.0 |
| rack | rack | >= 3.1.0, < 3.1.5, 3.1.0 |
Timeline
- CVE Published
- Jan 21, 1970 Security Advisory
- Jul 3, 2024 EPSS Score
- Jul 25, 2024 EPSS Score
- Aug 15, 2024 EPSS Score
- Sep 28, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 19, 2024 EPSS Score
- Oct 30, 2024 PoC Published
- Nov 10, 2024 EPSS Score
- Dec 3, 2024 EPSS Score
- Jan 15, 2025 EPSS Score
References
- https://github.com/rack/rack package
- https://github.com/rack/rack/security/advisories/GHSA-cj83-2ww7-mvq7 url
- https://github.com/rack/rack/security/advisories/GHSA-54rr-7fvw-6x8f url
- https://github.com/rack/rack/commit/412c980450ca729ee37f90a2661f166a9665e058 url
- https://nvd.nist.gov/vuln/detail/CVE-2024-39316 advisory
- https://advisory.dw1.io/61 url
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rack/CVE-2024-39316.yml url