CVE-2024-26141

Aliases:DEBIAN-CVE-2024-26141CGA-296c-7r2f-c338CGA-6cf3-m5m4-gw69CGA-fq8v-g788-mjr7CGA-gwc3-47hf-99jrCGA-hp3g-jjq5-wqr9CGA-jv7x-9xf9-jwf6CGA-qcrh-hv42-9w9qCGA-qh2w-cg3p-ppp3CGA-qpx7-p97c-frf5CGA-r5q4-x4jr-53r8CGA-vcc2-q4j6-mf8hCGA-w37v-26x4-33v8
Analyzed
Published: 28 Feb 2024, 23:28
Last modified:13 Feb 2025, 17:41

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
1.61% LOW
2% probability +1.32%
KEV
Not listed
Ransomware
No reports
Public exploits
3 found
Dark Web
Not detected

Timeline

28 Feb 2024, 23:28
Published
Vulnerability first disclosed
13 Feb 2025, 17:41
Last Modified
Vulnerability information updated

Description

Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with such large responses could lead to a denial of service issue. Vulnerable applications will use the `Rack::File` middleware or the `Rack::Utils.byte_ranges` methods (this includes Rails applications). The vulnerability is fixed in 3.0.9.1 and 2.2.8.1.

CVSS Metrics

  • v3.1MEDIUMScore: 5.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 1.61% Percentile: 75%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • chainguardkube-fluentd-operator

    < 1.18.2-r3

  • chainguardkube-fluentd-operator-compat

    < 1.18.2-r3

  • chainguardkube-fluentd-operator-default-config

    < 1.18.2-r3

  • chainguardkube-fluentd-operator-oci-entrypoint

    < 1.18.2-r3

  • chainguardruby3.2-rack

    < 3.0.9.1-r0

  • chainguardruby3.2-rack-2.2

    < 2.2.8.1-r0

  • wolfikube-fluentd-operator

    < 1.18.2-r3

  • wolfikube-fluentd-operator-compat

    < 1.18.2-r3

  • wolfikube-fluentd-operator-default-config

    < 1.18.2-r3

  • wolfikube-fluentd-operator-oci-entrypoint

    < 1.18.2-r3

  • wolfiruby3.2-rack

    < 3.0.9.1-r0

  • wolfiruby3.2-rack-2.2

    < 2.2.8.1-r0

  • debianruby-rack

    < 2.1.4-3+deb11u2 | < 2.2.6.4-1+deb12u1 | < 2.2.7-1.1 | < 2.2.7-1.1

  • debiandebian_linux

    10.0

  • rackrack

    ≥ 1.3.0, < 2.2.8.1 | ≥ 3.0.0, < 3.0.9.1

References (10)