Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-41817

Опубликовано: 15 нояб. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.

A flaw was found in ruby, where the date object was found to be vulnerable to a regular expression denial of service (ReDoS) during the parsing of dates. This flaw allows an attacker to hang a ruby application by providing a specially crafted date string. The highest threat to this vulnerability is system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6rubyOut of support scope
Red Hat Enterprise Linux 7rubyWill not fix
Red Hat Enterprise Linux 9rubyNot affected
Red Hat Enterprise Linux 8rubyFixedRHSA-2022:054316.02.2022
Red Hat Enterprise Linux 8rubyFixedRHSA-2022:577901.08.2022
Red Hat Enterprise Linux 8rubyFixedRHSA-2022:644713.09.2022
Red Hat Enterprise Linux 8rubyFixedRHSA-2022:645013.09.2022
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsrubyFixedRHSA-2022:058121.02.2022
Red Hat Enterprise Linux 8.2 Extended Update SupportrubyFixedRHSA-2022:058221.02.2022
Red Hat Enterprise Linux 8.4 Extended Update SupportrubyFixedRHSA-2022:054416.02.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2025104ruby: Regular expression denial of service vulnerability of Date parsing methods

EPSS

Процентиль: 61%
0.00422
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.

CVSS3: 7.5
nvd
больше 3 лет назад

Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.

CVSS3: 7.5
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 3 лет назад

Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regula ...

CVSS3: 7.5
github
больше 3 лет назад

Regular expression denial of service vulnerability (ReDoS) in date

EPSS

Процентиль: 61%
0.00422
Низкий

7.5 High

CVSS3