A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rack | Rack_project | * | 2.0.9.1 (excluding) |
Rack | Rack_project | 2.1.0 (including) | 2.1.4.1 (excluding) |
Rack | Rack_project | 2.2.0 (including) | 2.2.3.1 (excluding) |
Logging subsystem for Red Hat OpenShift 5.4 | RedHat | openshift-logging/fluentd-rhel8:v1.14.5-51 | * |
Red Hat Enterprise Linux 7 | RedHat | pcs-0:0.9.169-3.el7_9.3 | * |
Red Hat Gluster Storage 3.5 for RHEL 7 | RedHat | rubygem-rack-0:2.2.4-1.el7rhgs | * |
Ruby-rack | Ubuntu | bionic | * |
Ruby-rack | Ubuntu | esm-apps/bionic | * |
Ruby-rack | Ubuntu | esm-apps/focal | * |
Ruby-rack | Ubuntu | esm-apps/jammy | * |
Ruby-rack | Ubuntu | esm-apps/xenial | * |
Ruby-rack | Ubuntu | focal | * |
Ruby-rack | Ubuntu | impish | * |
Ruby-rack | Ubuntu | jammy | * |
Ruby-rack | Ubuntu | trusty/esm | * |
Ruby-rack | Ubuntu | upstream | * |
Ruby-rack | Ubuntu | xenial | * |