CVE-2011-5036

Description

Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

Risk Information

Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
1.278

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2011-5036 are fixed in Ruby-rack 1.1.3Windows
Vulnerabilities CVE-2011-5036 are fixed in Ruby-rack 1.2.5Windows
Vulnerabilities CVE-2011-5036 are fixed in Ruby-rack 1.3.6Windows
Vulnerabilities CVE-2011-5036 are fixed in Jruby - jruby-parent 1.6.5.1Windows
Vulnerabilities CVE-2011-5036 are fixed in Ruby-rack for Linux 1.1.3Linux
Vulnerabilities CVE-2011-5036 are fixed in Ruby-rack for Linux 1.2.5Linux
Vulnerabilities CVE-2011-5036 are fixed in Ruby-rack for Linux 1.3.6Linux
Vulnerabilities CVE-2011-5036 are fixed in Jruby - jruby-parent for Linux 1.6.5.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234