CVE-2023-27539
Advisory lineage Upstream: 0 Downstream: 23
Analyzed
Published: 09 Jan 2025, 00:33
Last modified:09 Jan 2025, 21:24
Vulnerability Summary
Overall Risk (default)
low
21/100 CVSS Score
5.3 MEDIUM
v3.1 (cve.org)
EPSS Score
0.36% LOW
0% probability +0.15%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
09 Jan 2025, 00:33
Published
Vulnerability first disclosed
09 Jan 2025, 21:24
Last Modified
Vulnerability information updated
Description
There is a denial of service vulnerability in the header parsing component of Rack.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- v3.1•MEDIUM•Score: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Trends
Current EPSS score: 0.36%• Percentile: 59%
Affected Systems
- debian•debian_linux
10.0 | 11.0
- rack•rack
≥ 2.0.0, < 2.2.6.4 | ≥ 3.0.0, < 3.0.6.1
- rails•rack
≥ 2.2.6.4, < 2.2.6.4 | ≥ 3.0.6.1, < 3.0.6.1
References (7)
- https://discuss.rubyonrails.org/t/cve-2023-27539-possible-denial-of-service-vulnerability-in-racks-header-parsing/82466
- https://github.com/advisories/GHSA-c6qg-cjj8-47qp
- https://github.com/rack/rack/commit/231ef369ad0b542575fb36c74fcfcfabcf6c530c
- https://github.com/rack/rack/commit/ee7919ea04303717858be1c3f16b406adc6d8cff
- https://lists.debian.org/debian-lts-announce/2023/04/msg00017.html
- https://security.netapp.com/advisory/ntap-20231208-0016/
- https://www.debian.org/security/2023/dsa-5530