Oval Definition:oval:org.opensuse.security:def:202122902
Revision Date:2022-06-30Version:1
Title:CVE-2021-22902
Description:

The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic backtracking in the regular expression engine.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2021-22902
SUSE CVE-2021-22902
Platform(s):openSUSE Tumbleweed
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • ruby2.7-rubygem-actionpack-6.0-6.0.4-1.2 is installed
  • OR ruby3.0-rubygem-actionpack-6.0-6.0.4-1.2 is installed
  • OR ruby3.1-rubygem-actionpack-6.0-6.0.4.4-1.1 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND rubygem-actionpack-4_2 is not affected
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND ruby2.1-rubygem-actionpack-4_2 is not affected
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 9 is installed
  • AND ruby2.1-rubygem-actionpack-4_2 is not affected
  • BACK