V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2016-0751
DEB
High

actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x be…

CVSS
7.5
High
EPSS
0.09
p92
Published
2016-01-01
Updated
2016-01-01
Description

actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly restrict use of the MIME type cache, which allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP Accept header.

Tags · CWE
Pre-auth
CWE-399
CWE-770
CAPEC-125
CAPEC-130
CAPEC-147
CAPEC-197
CAPEC-229
CAPEC-230
CAPEC-231
CAPEC-469
CAPEC-482
CAPEC-486
CAPEC-487
CAPEC-488
CAPEC-489
CAPEC-490
CAPEC-491
CAPEC-493
CAPEC-494
CAPEC-495
CAPEC-496
CAPEC-528
Affected products
RailsRailsRailsRailsRailsRailsRailsRailsRailsRailsRailsRailsRailsRails-4.0Rh-ror41-rubygem-actionpackRh-ror41-rubygem-actionpackRh-ror41-rubygem-actionpackRh-ror41-rubygem-actionpackRh-ror41-rubygem-actionpackRh-ror41-rubygem-actionpack
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Timeline
2016-01-01
Published
2016-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.089 · p92
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-125 · CWE-770
└ via CAPEC-490 · CWE-770
└ via CAPEC-125 · CWE-770
└ via CAPEC-482 · CWE-770
└ via CAPEC-469 · CWE-770
└ via CAPEC-130 · CWE-770
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
railsTracked
railsTracked
railsTracked
railsTracked
railsTracked
railsTracked
railsTracked
railsTracked
railsTracked
railsTracked
railsTracked
railsTracked
railsTracked
rails-4.0Tracked
rh-ror41-rubygem-actionpackTracked
rh-ror41-rubygem-actionpackTracked
rh-ror41-rubygem-actionpackTracked
rh-ror41-rubygem-actionpackTracked
rh-ror41-rubygem-actionpackTracked
rh-ror41-rubygem-actionpackTracked
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities