CVE-2015-3225
lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.
- Affected products
- Centos, Rack, Red Hat, Ruby On Rails, Suse
- Rack Project Rack
- ≤ 1.5.3, 1.6.0, 1.6.1
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 8.0% (94th percentile)
- Weakness
- CWE-19
- NVD status
- Modified
- Published
- 2015-07-26
CVE-2015-3225 at NVD
No indexed exploits for CVE-2015-3225 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2015-3225 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.