Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-22880

Опубликовано: 11 фев. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the money type of the PostgreSQL adapter in Active Record to spend too much time in a regular expression, resulting in the potential for a DoS attack. This only impacts Rails applications that are using PostgreSQL along with money type columns that take user input.

The PostgreSQL adapter in Active Record suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the money type of the PostgreSQL adapter in Active Record to spend too much time in a regular expression, resulting in the potential for a DoS attack. This only impacts Rails applications that are using PostgreSQL along with money type columns that take user input.

Отчет

Red Hat Satellite ship affected version of rubygem-activerecord however, the product is not vulnerable to the flaw as it does not use the money field type in product code. We may update the rubygem-activerecord dependency in a future release.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5cfme-gemsetWill not fix
Red Hat 3scale API Management Platform 2rubygem-activerecordWill not fix
Red Hat 3scale API Management Platform 2systemAffected
Red Hat Satellite 6tfm-ror52-rubygem-activerecordWill not fix
Red Hat Satellite 6tfm-rubygem-activerecordFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1930102rubygem-activerecord: crafted input may cause a regular expression DoS

EPSS

Процентиль: 85%
0.02459
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` type of the PostgreSQL adapter in Active Record to spend too much time in a regular expression, resulting in the potential for a DoS attack. This only impacts Rails applications that are using PostgreSQL along with money type columns that take user input.

CVSS3: 7.5
nvd
почти 5 лет назад

The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` type of the PostgreSQL adapter in Active Record to spend too much time in a regular expression, resulting in the potential for a DoS attack. This only impacts Rails applications that are using PostgreSQL along with money type columns that take user input.

CVSS3: 7.5
debian
почти 5 лет назад

The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4 ...

suse-cvrf
около 4 лет назад

Security update for rubygem-activerecord-5_1

suse-cvrf
около 4 лет назад

Security update for rubygem-activerecord-5_1

EPSS

Процентиль: 85%
0.02459
Низкий

7.5 High

CVSS3