CVE-2023-22795

A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header. A specially crafted HTTP If-None-Match header can cause the regular expression engine to enter a state of catastrophic backtracking, when on a version of Ruby below 3.2.0. This can cause the process to use large amounts of CPU and memory, leading to a possible DoS vulnerability All users running an affected release should either upgrade or use one of the workarounds immediately.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
hackeroneCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
VendorProductVersion
rubyonrailsrails
𝑥
< 6.1.7.1
rubyonrailsrails
7.0.0 ≤
𝑥
< 7.0.4.1
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rails
bullseye (security)
2:6.0.3.7+dfsg-2+deb11u2
fixed
bullseye
2:6.0.3.7+dfsg-2+deb11u2
fixed
bookworm
2:6.1.7.3+dfsg-2~deb12u1
fixed
trixie
2:6.1.7.3+dfsg-4
fixed
sid
2:6.1.7.3+dfsg-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rails
oracular
needs-triage
noble
needs-triage
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
needs-triage
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
ignored
rails-4.0
kinetic
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
ignored
ruby-actionpack-3.2
kinetic
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
ignored
ruby-activemodel-3.2
kinetic
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
ignored
ruby-activerecord-3.2
kinetic
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
ignored
ruby-activesupport-3.2
kinetic
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
ignored
ruby-rails-3.2
kinetic
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
ignored