CVE Vulnerabilities

CVE-2015-7581

Published: Feb 16, 2016 | Modified: Aug 08, 2019
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

actionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in Ruby on Rails 4.x before 4.2.5.1 and 5.x before 5.0.0.beta1.1 allows remote attackers to cause a denial of service (superfluous caching and memory consumption) by leveraging an applications use of a wildcard controller route.

Affected Software

Name Vendor Start Version End Version
Rails Rubyonrails 4.0.0 (including) 4.0.0 (including)
Rails Rubyonrails 4.0.0-beta (including) 4.0.0-beta (including)
Rails Rubyonrails 4.0.0-rc1 (including) 4.0.0-rc1 (including)
Rails Rubyonrails 4.0.0-rc2 (including) 4.0.0-rc2 (including)
Rails Rubyonrails 4.0.1 (including) 4.0.1 (including)
Rails Rubyonrails 4.0.1-rc1 (including) 4.0.1-rc1 (including)
Rails Rubyonrails 4.0.1-rc2 (including) 4.0.1-rc2 (including)
Rails Rubyonrails 4.0.1-rc3 (including) 4.0.1-rc3 (including)
Rails Rubyonrails 4.0.1-rc4 (including) 4.0.1-rc4 (including)
Rails Rubyonrails 4.0.2 (including) 4.0.2 (including)
Rails Rubyonrails 4.0.3 (including) 4.0.3 (including)
Rails Rubyonrails 4.0.4 (including) 4.0.4 (including)
Rails Rubyonrails 4.0.5 (including) 4.0.5 (including)
Rails Rubyonrails 4.0.6 (including) 4.0.6 (including)
Rails Rubyonrails 4.0.6-rc1 (including) 4.0.6-rc1 (including)
Rails Rubyonrails 4.0.6-rc2 (including) 4.0.6-rc2 (including)
Rails Rubyonrails 4.0.6-rc3 (including) 4.0.6-rc3 (including)
Rails Rubyonrails 4.0.7 (including) 4.0.7 (including)
Rails Rubyonrails 4.0.8 (including) 4.0.8 (including)
Rails Rubyonrails 4.0.9 (including) 4.0.9 (including)
Rails Rubyonrails 4.0.10-rc1 (including) 4.0.10-rc1 (including)
Rails Rubyonrails 4.1.0 (including) 4.1.0 (including)
Rails Rubyonrails 4.1.0-beta1 (including) 4.1.0-beta1 (including)
Rails Rubyonrails 4.1.1 (including) 4.1.1 (including)
Rails Rubyonrails 4.1.2 (including) 4.1.2 (including)
Rails Rubyonrails 4.1.2-rc1 (including) 4.1.2-rc1 (including)
Rails Rubyonrails 4.1.2-rc2 (including) 4.1.2-rc2 (including)
Rails Rubyonrails 4.1.2-rc3 (including) 4.1.2-rc3 (including)
Rails Rubyonrails 4.1.3 (including) 4.1.3 (including)
Rails Rubyonrails 4.1.4 (including) 4.1.4 (including)
Rails Rubyonrails 4.1.5 (including) 4.1.5 (including)
Rails Rubyonrails 4.1.6-rc1 (including) 4.1.6-rc1 (including)
Rails Rubyonrails 4.1.7 (including) 4.1.7 (including)
Rails Rubyonrails 4.1.8 (including) 4.1.8 (including)
Rails Rubyonrails 4.2.0-beta1 (including) 4.2.0-beta1 (including)
Rails Rubyonrails 4.2.1 (including) 4.2.1 (including)
Rails Rubyonrails 4.2.2 (including) 4.2.2 (including)
Rails Rubyonrails 4.2.3 (including) 4.2.3 (including)
Rails Rubyonrails 4.2.4 (including) 4.2.4 (including)
Rails Rubyonrails 4.2.5 (including) 4.2.5 (including)
Rails Rubyonrails 5.0.0-beta1 (including) 5.0.0-beta1 (including)

References