{"id":"GHSA-v6j3-7jrw-hq2p","summary":"Rack Gem Subject to Denial of Service via Hash Collisions","details":"Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.","aliases":["CVE-2011-5036"],"modified":"2024-11-30T05:33:19.217010Z","published":"2022-05-17T04:59:13Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-03-27T16:12:55Z","nvd_published_at":"2011-12-30T01:55:00Z","cwe_ids":["CWE-328","CWE-400"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-5036"},{"type":"WEB","url":"https://gist.github.com/52bbc6b9cc19ce330829"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rack/CVE-2011-5036.yml"},{"type":"WEB","url":"https://web.archive.org/web/20120201040317/http://jruby.org/2011/12/27/jruby-1-6-5-1"},{"type":"WEB","url":"https://web.archive.org/web/20130213132312/http://archives.neohapsis.com/archives/bugtraq/2011-12/0181.html"},{"type":"WEB","url":"http://www.debian.org/security/2013/dsa-2783"},{"type":"WEB","url":"http://www.kb.cert.org/vuls/id/903934"},{"type":"WEB","url":"http://www.nruns.com/_downloads/advisory28122011.pdf"},{"type":"WEB","url":"http://www.ocert.org/advisories/ocert-2011-003.html"}],"affected":[{"package":{"name":"rack","ecosystem":"RubyGems","purl":"pkg:gem/rack"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.3"}]}],"versions":["0.1.0","0.2.0","0.3.0","0.4.0","0.9.0","0.9.1","1.0.0","1.0.1","1.1.0","1.1.1","1.1.1.pre","1.1.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-v6j3-7jrw-hq2p/GHSA-v6j3-7jrw-hq2p.json"}},{"package":{"name":"rack","ecosystem":"RubyGems","purl":"pkg:gem/rack"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.2.0"},{"fixed":"1.2.5"}]}],"versions":["1.2.0","1.2.1","1.2.2","1.2.3","1.2.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-v6j3-7jrw-hq2p/GHSA-v6j3-7jrw-hq2p.json"}},{"package":{"name":"rack","ecosystem":"RubyGems","purl":"pkg:gem/rack"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.3.0"},{"fixed":"1.3.6"}]}],"versions":["1.3.0","1.3.1","1.3.2","1.3.3","1.3.4","1.3.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-v6j3-7jrw-hq2p/GHSA-v6j3-7jrw-hq2p.json"}},{"package":{"name":"org.jruby:jruby-parent","ecosystem":"Maven","purl":"pkg:maven/org.jruby/jruby-parent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.5.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-v6j3-7jrw-hq2p/GHSA-v6j3-7jrw-hq2p.json"}}],"schema_version":"1.9.0"}