CVE Vulnerabilities

CVE-2023-27539

Published: Jan 09, 2025 | Modified: Oct 10, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

There is a denial of service vulnerability in the header parsing component of Rack.

Affected Software

NameVendorStart VersionEnd Version
RackRack2.0.0 (including)2.2.6.4 (excluding)
RackRack3.0.0 (including)3.0.6.1 (excluding)
Red Hat Enterprise Linux 8RedHatpcs-0:0.10.15-4.el8_8.1*
Red Hat Enterprise Linux 8.4 Extended Update SupportRedHatpcs-0:0.10.8-1.el8_4.4*
Red Hat Enterprise Linux 8.6 Extended Update SupportRedHatpcs-0:0.10.12-6.el8_6.4*
Red Hat Enterprise Linux 9RedHatpcs-0:0.11.4-7.el9_2*
Red Hat Enterprise Linux 9.0 Extended Update SupportRedHatpcs-0:0.11.1-10.el9_0.4*
Red Hat Satellite 6.14 for RHEL 8RedHatrubygem-rack-0:2.2.7-1.el8sat*
Red Hat Satellite 6.14 for RHEL 8RedHatrubygem-rack-0:2.2.7-1.el8sat*
RHOL-5.6-RHEL-8RedHatopenshift-logging/fluentd-rhel8:v1.14.6-113*
RHOL-5.7-RHEL-8RedHatopenshift-logging/fluentd-rhel8:v1.14.6-140*
Ruby-rackUbuntubionic*
Ruby-rackUbuntuesm-apps/bionic*
Ruby-rackUbuntuesm-apps/focal*
Ruby-rackUbuntuesm-apps/jammy*
Ruby-rackUbuntuesm-apps/xenial*
Ruby-rackUbuntuesm-infra-legacy/trusty*
Ruby-rackUbuntufocal*
Ruby-rackUbuntujammy*
Ruby-rackUbuntukinetic*
Ruby-rackUbuntulunar*
Ruby-rackUbuntumantic*
Ruby-rackUbuntutrusty*
Ruby-rackUbuntutrusty/esm*
Ruby-rackUbuntuupstream*
Ruby-rackUbuntuxenial*

References