Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-22799

Опубликовано: 09 фев. 2023
Источник: debian

Описание

A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-globalidfixed0.6.0-2package
ruby-globalidno-dsabullseyepackage
ruby-globalidno-dsabusterpackage

Примечания

  • https://discuss.rubyonrails.org/t/cve-2023-22799-possible-redos-based-dos-vulnerability-in-globalid/82127

  • https://github.com/rails/globalid/commit/3bc4349422e60f2235876a59dd415e98b072eb2b (v1.1.0)

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately.

CVSS3: 7.5
redhat
больше 2 лет назад

A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately.

CVSS3: 7.5
nvd
больше 2 лет назад

A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately.

suse-cvrf
больше 2 лет назад

Security update for rubygem-globalid

github
больше 2 лет назад

ReDoS based DoS vulnerability in GlobalID