Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-22799

Опубликовано: 20 янв. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately.

A flaw was found in rubygem-globalid. RubyGem’s GlobalID gem is vulnerable to a denial of service issue caused by a regular expression denial of service (ReDoS) flaw in the model name parsing. By sending a specially-crafted regex input, a remote attacker can cause a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp-zync-containerWill not fix
Red Hat Satellite 6.14 for RHEL 8rubygem-globalidFixedRHSA-2023:681808.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2164730rubygem-globalid: ReDoS vulnerability

EPSS

Процентиль: 77%
0.01082
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately.

CVSS3: 7.5
nvd
больше 2 лет назад

A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately.

CVSS3: 7.5
debian
больше 2 лет назад

A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could all ...

suse-cvrf
больше 2 лет назад

Security update for rubygem-globalid

github
больше 2 лет назад

ReDoS based DoS vulnerability in GlobalID

EPSS

Процентиль: 77%
0.01082
Низкий

7.5 High

CVSS3