CVE-2024-25126 Affecting logstash package, versions <8.12.2-r2
Threat Intelligence
EPSS
0.04% (12th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-WOLFILATEST-LOGSTASH-6422185
- published 12 Mar 2024
- disclosed 29 Feb 2024
Introduced: 29 Feb 2024
CVE-2024-25126 Open this link in a new tabHow to fix?
Upgrade Wolfi
logstash
to version 8.12.2-r2 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream logstash
package and not the logstash
package as distributed by Wolfi
.
See How to fix?
for Wolfi
relevant fixed versions and status.
Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). This vulnerability is patched in 3.0.9.1 and 2.2.8.1.
References
- https://discuss.rubyonrails.org/t/denial-of-service-vulnerability-in-rack-content-type-parsing/84941
- https://github.com/rack/rack/commit/6efb2ceea003c4b195815a614e00438cbd543462
- https://github.com/rack/rack/commit/d9c163a443b8cadf4711d84bd2c58cb9ef89cf49
- https://github.com/rack/rack/security/advisories/GHSA-22f2-v57c-j9cx
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rack/CVE-2024-25126.yml
- https://lists.debian.org/debian-lts-announce/2024/04/msg00022.html
- https://security.netapp.com/advisory/ntap-20240510-0005/
CVSS Scores
version 3.1