Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8hc4-xxm3-5ppp

Опубликовано: 02 мар. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Active Record subject to Regular Expression Denial-of-Service (ReDoS)

The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the money type of the PostgreSQL adapter in Active Record to spend too much time in a regular expression, resulting in the potential for a DoS attack. This only impacts Rails applications that are using PostgreSQL along with money type columns that take user input.

Пакеты

Наименование

activerecord

rubygems
Затронутые версииВерсия исправления

>= 5.0.0, <= 5.2.4.4

5.2.4.5

Наименование

activerecord

rubygems
Затронутые версииВерсия исправления

>= 6.0.0, <= 6.0.3.4

6.0.3.5

Наименование

activerecord

rubygems
Затронутые версииВерсия исправления

>= 6.1.0, <= 6.1.2.0

6.1.2.1

EPSS

Процентиль: 85%
0.02459
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` type of the PostgreSQL adapter in Active Record to spend too much time in a regular expression, resulting in the potential for a DoS attack. This only impacts Rails applications that are using PostgreSQL along with money type columns that take user input.

CVSS3: 7.5
redhat
почти 5 лет назад

The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` type of the PostgreSQL adapter in Active Record to spend too much time in a regular expression, resulting in the potential for a DoS attack. This only impacts Rails applications that are using PostgreSQL along with money type columns that take user input.

CVSS3: 7.5
nvd
почти 5 лет назад

The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` type of the PostgreSQL adapter in Active Record to spend too much time in a regular expression, resulting in the potential for a DoS attack. This only impacts Rails applications that are using PostgreSQL along with money type columns that take user input.

CVSS3: 7.5
debian
почти 5 лет назад

The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4 ...

suse-cvrf
около 4 лет назад

Security update for rubygem-activerecord-5_1

EPSS

Процентиль: 85%
0.02459
Низкий

7.5 High

CVSS3

Дефекты

CWE-400