#VU15971 Resource exhaustion in Rack - CVE-2018-16470
Published: November 19, 2018 / Updated: November 20, 2018
Rack
Rack
Description
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to resource exhaustion condition in the multipart parser when processing malicious input. A remote attacker can send a custom request, cause the parser to use an excessive amount of CPU resources and cause the service to crash.