VYPR
Moderate severityNVD Advisory· Published Jul 26, 2015· Updated May 6, 2026

CVE-2015-3225

CVE-2015-3225

Description

lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
rackRubyGems
>= 1.5.0, < 1.5.41.5.4
rackRubyGems
>= 1.6.0, < 1.6.21.6.2
rackRubyGems
>= 1.4.0, < 1.4.61.4.6

Affected products

7
  • Rack Project/Rack3 versions
    cpe:2.3:a:rack_project:rack:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:rack_project:rack:*:*:*:*:*:*:*:*range: <=1.5.3
    • cpe:2.3:a:rack_project:rack:1.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:rack_project:rack:1.6.1:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
  • OpenSUSE/openSUSE2 versions
    cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
    • cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

15

News mentions

0

No linked articles in our index yet.