CVE-2024-0241

encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by sending an HTTP request with an extremely long "id" parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:diaconou:encodedid\:\:rails:*:*:*:*:*:ruby:*:*
cpe:2.3:a:diaconou:encodedid\:\:rails:1.0.0:-:*:*:*:ruby:*:*
cpe:2.3:a:diaconou:encodedid\:\:rails:1.0.0:beta1:*:*:*:ruby:*:*

History

No history.

Information

Published : 2024-01-04 21:15

Updated : 2024-01-10 15:11


NVD link : CVE-2024-0241

Mitre link : CVE-2024-0241

CVE.ORG link : CVE-2024-0241


JSON object : View

Products Affected

diaconou

  • encodedid\
CWE
CWE-770

Allocation of Resources Without Limits or Throttling

CWE-400

Uncontrolled Resource Consumption