Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhwm-jh88-3gjf

Опубликовано: 03 мар. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.3
CVSS3: 4

Описание

CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement

There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem.

Details

The regular expression used in CGI::Util#escapeElement is vulnerable to ReDoS. The crafted input could lead to a high CPU consumption.

This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later.

Affected versions

cgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1.

Credits

Thanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability.

Пакеты

Наименование

cgi

rubygems
Затронутые версииВерсия исправления

< 0.3.5.1

0.3.5.1

Наименование

cgi

rubygems
Затронутые версииВерсия исправления

= 0.3.6

0.3.7

Наименование

cgi

rubygems
Затронутые версииВерсия исправления

>= 0.4.0, < 0.4.2

0.4.2

EPSS

Процентиль: 33%
0.00126
Низкий

6.3 Medium

CVSS4

4 Medium

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 4
ubuntu
4 месяца назад

In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.

CVSS3: 5.3
redhat
4 месяца назад

In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.

CVSS3: 4
nvd
4 месяца назад

In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.

CVSS3: 7.5
msrc
3 месяца назад

Описание отсутствует

CVSS3: 4
debian
4 месяца назад

In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of S ...

EPSS

Процентиль: 33%
0.00126
Низкий

6.3 Medium

CVSS4

4 Medium

CVSS3

Дефекты

CWE-1333