Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-22799

Опубликовано: 09 фев. 2023
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rubyonrails:globalid:*:*:*:*:*:ruby:*:*
Версия от 0.2.1 (включая) до 1.0.1 (исключая)

EPSS

Процентиль: 66%
0.00509
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-1333

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately.

CVSS3: 7.5
redhat
больше 2 лет назад

A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately.

CVSS3: 7.5
debian
больше 2 лет назад

A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could all ...

suse-cvrf
больше 2 лет назад

Security update for rubygem-globalid

github
больше 2 лет назад

ReDoS based DoS vulnerability in GlobalID

EPSS

Процентиль: 66%
0.00509
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-1333