CVE Vulnerabilities

CVE-2023-27539

Published: Jan 09, 2025 | Modified: Oct 10, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM

There is a denial of service vulnerability in the header parsing component of Rack.

Affected Software

Name Vendor Start Version End Version
Rack Rack 2.0.0 (including) 2.2.6.4 (excluding)
Rack Rack 3.0.0 (including) 3.0.6.1 (excluding)
Red Hat Enterprise Linux 8 RedHat pcs-0:0.10.15-4.el8_8.1 *
Red Hat Enterprise Linux 8.4 Extended Update Support RedHat pcs-0:0.10.8-1.el8_4.4 *
Red Hat Enterprise Linux 8.6 Extended Update Support RedHat pcs-0:0.10.12-6.el8_6.4 *
Red Hat Enterprise Linux 9 RedHat pcs-0:0.11.4-7.el9_2 *
Red Hat Enterprise Linux 9.0 Extended Update Support RedHat pcs-0:0.11.1-10.el9_0.4 *
Red Hat Satellite 6.14 for RHEL 8 RedHat rubygem-rack-0:2.2.7-1.el8sat *
Red Hat Satellite 6.14 for RHEL 8 RedHat rubygem-rack-0:2.2.7-1.el8sat *
RHOL-5.6-RHEL-8 RedHat openshift-logging/fluentd-rhel8:v1.14.6-113 *
RHOL-5.7-RHEL-8 RedHat openshift-logging/fluentd-rhel8:v1.14.6-140 *
Ruby-rack Ubuntu bionic *
Ruby-rack Ubuntu esm-apps/bionic *
Ruby-rack Ubuntu esm-apps/focal *
Ruby-rack Ubuntu esm-apps/jammy *
Ruby-rack Ubuntu esm-apps/xenial *
Ruby-rack Ubuntu esm-infra-legacy/trusty *
Ruby-rack Ubuntu focal *
Ruby-rack Ubuntu jammy *
Ruby-rack Ubuntu kinetic *
Ruby-rack Ubuntu lunar *
Ruby-rack Ubuntu mantic *
Ruby-rack Ubuntu trusty *
Ruby-rack Ubuntu trusty/esm *
Ruby-rack Ubuntu upstream *
Ruby-rack Ubuntu xenial *

References