« Back to list

CVE-2011-5036

Status: ModifiedMedium (5)—

Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2011-5036",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-12-30T01:55:01.687",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2011-12/0181.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.debian.org/security/2013/dsa-2783",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/903934",
      "tags": [
        "US Government Resource"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.nruns.com/_downloads/advisory28122011.pdf",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ocert.org/advisories/ocert-2011-003.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://gist.github.com/52bbc6b9cc19ce330829",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2011-12/0181.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2013/dsa-2783",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/903934",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.nruns.com/_downloads/advisory28122011.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ocert.org/advisories/ocert-2011-003.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://gist.github.com/52bbc6b9cc19ce330829",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-310"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters."
    },
    {
      "lang": "es",
      "value": "Rack anterior a v1.1.3, v1.2.x anterior a v1.2.5, v1.3.6 y v1.3.x calcula los valores hash de los parámetros de forma, sin restringir la capacidad de desencadenar colisiones hash predecible, lo que permite a atacantes remotos provocar una denegación de servicio (CPU consumo) mediante el envío de gran cantidad de parámetros a mano."
    }
  ],
  "lastModified": "2026-06-16T23:35:49.233",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:rack_project:rack:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FC25AA62-8839-47F9-B215-8B08343D4DE2",
              "versionEndIncluding": "1.1.0"
            },
            {
              "criteria": "cpe:2.3:a:rack_project:rack:1.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F4ECE38D-E0CA-4C37-B6A7-385F90FA3BC6"
            },
            {
              "criteria": "cpe:2.3:a:rack_project:rack:1.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8B347613-F3F6-490C-AAE7-A5054B7D2892"
            },
            {
              "criteria": "cpe:2.3:a:rack_project:rack:1.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FDA365EF-8CF1-4040-9353-00F0BF0499C0"
            },
            {
              "criteria": "cpe:2.3:a:rack_project:rack:1.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A27A3B18-AB5A-4F99-AD51-12870745D9FA"
            },
            {
              "criteria": "cpe:2.3:a:rack_project:rack:1.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C207F012-CEEE-4173-A64D-61A8E8E02533"
            },
            {
              "criteria": "cpe:2.3:a:rack_project:rack:1.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "98CBCA07-8EEC-49D0-8C17-7887ABB63ED6"
            },
            {
              "criteria": "cpe:2.3:a:rack_project:rack:1.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "93B65658-8E1B-4832-822A-1C3770B33BB9"
            },
            {
              "criteria": "cpe:2.3:a:rack_project:rack:1.3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E9E3412-6D9C-46FC-806E-0E0D310D4DDE"
            },
            {
              "criteria": "cpe:2.3:a:rack_project:rack:1.3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "10A95FAF-3314-4F3F-8619-DAED41648AE3"
            },
            {
              "criteria": "cpe:2.3:a:rack_project:rack:1.3.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00901558-9028-4BDF-AFE6-502DF2632069"
            },
            {
              "criteria": "cpe:2.3:a:rack_project:rack:1.3.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A8CBC63-DBA8-4A4E-87D7-5B891CDF7091"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}