Oval Definition:oval:org.opensuse.security:def:202122904
Revision Date:2022-09-02Version:1
Title:CVE-2021-22904
Description:

The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication logic in Action Controller due to a too permissive regular expression. Impacted code uses `authenticate_or_request_with_http_token` or `authenticate_with_http_token` for request authentication.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2021-22904
SUSE CVE-2021-22904
SUSE-SU-2022:2108-1
Platform(s):openSUSE Leap 15.4
openSUSE Tumbleweed
SUSE Linux Enterprise High Availability 15 SP2
SUSE Linux Enterprise High Availability 15 SP4
SUSE Linux Enterprise High Performance Computing 15 SP2
SUSE Linux Enterprise High Performance Computing 15 SP4
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP4
SUSE Manager Proxy 4.1
SUSE Manager Proxy 4.3
SUSE Manager Retail Branch Server 4.1
SUSE Manager Retail Branch Server 4.3
SUSE Manager Server 4.1
SUSE Manager Server 4.3
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • ruby2.7-rubygem-actionpack-5.2-5.2.6-1.2 is installed
  • OR ruby2.7-rubygem-actionpack-6.0-6.0.4-1.2 is installed
  • OR ruby3.0-rubygem-actionpack-5.2-5.2.6-1.2 is installed
  • OR ruby3.0-rubygem-actionpack-6.0-6.0.4-1.2 is installed
  • OR ruby3.1-rubygem-actionpack-6.0-6.0.4.4-1.1 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND ruby2.1-rubygem-actionpack-4_2 is affected
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 9 is installed
  • AND ruby2.1-rubygem-actionpack-4_2 is affected
  • Definition Synopsis
  • openSUSE Leap 15.4 is installed
  • AND Package Information
  • ruby2.5-rubygem-actionpack-5_1-5.1.4-150000.3.12.1 is installed
  • AND ruby2.5-rubygem-actionpack-5_1 is signed with openSUSE key
  • OR
  • ruby2.5-rubygem-actionpack-doc-5_1-5.1.4-150000.3.12.1 is installed
  • AND ruby2.5-rubygem-actionpack-doc-5_1 is signed with openSUSE key
  • OR
  • ruby2.5-rubygem-activesupport-5_1-5.1.4-150000.3.6.1 is installed
  • AND ruby2.5-rubygem-activesupport-5_1 is signed with openSUSE key
  • OR
  • ruby2.5-rubygem-activesupport-doc-5_1-5.1.4-150000.3.6.1 is installed
  • AND ruby2.5-rubygem-activesupport-doc-5_1 is signed with openSUSE key
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Availability 15 SP4 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP4 is installed
  • OR SUSE Linux Enterprise Server 15 SP4 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP4 is installed
  • OR SUSE Manager Proxy 4.3 is installed
  • OR SUSE Manager Retail Branch Server 4.3 is installed
  • OR SUSE Manager Server 4.3 is installed
  • AND Package Information
  • ruby2.5-rubygem-actionpack-5_1-5.1.4-150000.3.12.1 is installed
  • OR ruby2.5-rubygem-activesupport-5_1-5.1.4-150000.3.6.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Availability 15 SP2 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP2 is installed
  • OR SUSE Linux Enterprise Server 15 SP2 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
  • OR SUSE Manager Proxy 4.1 is installed
  • OR SUSE Manager Retail Branch Server 4.1 is installed
  • OR SUSE Manager Server 4.1 is installed
  • AND Package Information
  • ruby2.5-rubygem-actionpack-5_1-5.1.4-150000.3.12.1 is installed
  • OR ruby2.5-rubygem-activesupport-5_1-5.1.4-150000.3.6.1 is installed
  • BACK