{"id":"CVE-2013-0184","aliases":["GHSA-v882-ccj6-jc48"],"url":"https://o3.security/vulnerability/CVE-2013-0184","summary":"Rack vulnerable to Denial of Service","details":"Unspecified vulnerability in Rack::Auth::AbstractRequest in Rack 1.1.x before 1.1.5, 1.2.x before 1.2.7, 1.3.x before 1.3.9, and 1.4.x before 1.4.4 allows remote attackers to cause a denial of service via unknown vectors related to \"symbolized arbitrary strings.\"","published":"2013-03-01T05:40:17Z","modified":"2026-04-10T03:43:16.792794Z","cvss":null,"epss":{"score":0.02418,"percentile":0.82896,"asOf":"2026-08-22"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"rack","fixedVersion":"1.1.5"},{"ecosystem":"RubyGems","name":"rack","fixedVersion":"1.2.7"},{"ecosystem":"RubyGems","name":"rack","fixedVersion":"1.3.9"},{"ecosystem":"RubyGems","name":"rack","fixedVersion":"1.4.4"}],"fix":{"url":"https://github.com/rack/rack/commit/1f61549529d07abd4aa512b8320ab0e97dcacc5d","label":"rack/rack@1f61549"},"references":[{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2013-0544.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2013-0548.html"},{"type":"ADVISORY","url":"http://www.debian.org/security/2013/dsa-2783"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=895384"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-0184"},{"type":"WEB","url":"https://github.com/rack/rack/commit/1f61549529d07abd4aa512b8320ab0e97dcacc5d"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2013:0544"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2013:0548"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2013-0184"},{"type":"PACKAGE","url":"https://github.com/rack/rack"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T03:43:16.792794Z"}}