REDHAT-BUG-895384: Medium severity rack vulnerability
A flaw that was fixed in 1.4.4, 1.3.9, 1.2.7, and 1.1.5 was also announced [4] that creates a minor denial of service condition, this time in the Rack::Auth::AbstractRequest, where it symbolized arbitrary strings (apparently this has something to do with authentication, but there is no further information provided other than the fix [5] itself, which is noted as "a breaking API change").
[4] https://groups.google.com/forum/#!topic/rack-devel/ImYOqcGiksw/discussion [5] https://github.com/rack/rack/commit/0c76175fcccad74ba2f991c487d3669c28a297c8
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-895384?
The severity of REDHAT-BUG-895384 is considered minor as it causes a denial of service condition.
How do I fix REDHAT-BUG-895384?
To fix REDHAT-BUG-895384, upgrade to Rack version 1.4.4, 1.3.9, 1.2.7, or 1.1.5.
Which versions of Rack are affected by REDHAT-BUG-895384?
Rack versions between 1.1.5 and 1.4.4 are affected by REDHAT-BUG-895384.
What component is vulnerable in REDHAT-BUG-895384?
The vulnerable component in REDHAT-BUG-895384 is Rack::Auth::AbstractRequest.
Is REDHAT-BUG-895384 related to authentication issues?
Yes, REDHAT-BUG-895384 is related to authentication as it involves symbolizing arbitrary strings during the authentication process.