The vendor explicitly identifies these products as affected by this CVE.
- 3scale-amp2/zync-rhel7 as a component of Red Hat 3scale API Management Platform 2
- 3scale-amp2/zync-rhel8 as a component of Red Hat 3scale API Management Platform 2
- 3scale-amp2/zync-rhel9 as a component of Red Hat 3scale API Management Platform 2
- 3scale-amp21/zync as a component of Red Hat 3scale API Management Platform 2
- 3scale-amp22/zync as a component of Red Hat 3scale API Management Platform 2
- 3scale-amp24/zync as a component of Red Hat 3scale API Management Platform 2
- 3scale-amp25/zync as a component of Red Hat 3scale API Management Platform 2
- 3scale-amp26/zync as a component of Red Hat 3scale API Management Platform 2
- rhosp13/openstack-cinder-api as a component of Red Hat OpenStack Platform 13 (Queens)
- rhosp13/openstack-cinder-backup as a component of Red Hat OpenStack Platform 13 (Queens)
- rhosp13/openstack-cinder-scheduler as a component of Red Hat OpenStack Platform 13 (Queens)
- rhosp13/openstack-cinder-volume as a component of Red Hat OpenStack Platform 13 (Queens)
- Summary
- A flaw was found in Rack where Rack::Multipart::Parser stores non-file form fields entirely in memory without size limits. An attacker can send a multipart/form-data request with an extremely large text field, causing the server to allocate large amounts of memory which leads to a denial of service crash due to out-of-memory issue.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
