Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-28756

Опубликовано: 21 мар. 2023
Источник: redhat
CVSS3: 5.3

Описание

A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.

A flaw was found in the Time gem and Time library of Ruby. The Time parser mishandles invalid strings with specific characters and causes an increase in execution time for parsing strings to Time objects. This issue may result in a Regular expression denial of service (ReDoS).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6rubyOut of support scope
Red Hat Enterprise Linux 7rubyWill not fix
Red Hat Enterprise Linux 8ruby:2.6/rubyWill not fix
Red Hat Software Collectionsrh-ruby30-rubyWill not fix
Red Hat Enterprise Linux 8rubyFixedRHSA-2023:382127.06.2023
Red Hat Enterprise Linux 8rubyFixedRHSA-2023:702514.11.2023
Red Hat Enterprise Linux 8rubyFixedRHSA-2024:143119.03.2024
Red Hat Enterprise Linux 8rubyFixedRHSA-2024:350030.05.2024
Red Hat Enterprise Linux 9rubyFixedRHSA-2024:157601.04.2024
Red Hat Enterprise Linux 9rubyFixedRHSA-2024:383811.06.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 лет назад

A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.

CVSS3: 5.3
nvd
около 2 лет назад

A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.

CVSS3: 5.3
debian
около 2 лет назад

A ReDoS issue was discovered in the Time component through 0.2.1 in Ru ...

CVSS3: 7.5
github
около 2 лет назад

Ruby Time component ReDoS issue

CVSS3: 7.5
fstec
около 2 лет назад

Уязвимость библиотеки Time интерпретатора Ruby, позволяющая нарушителю вызвать отказ в обслуживании

5.3 Medium

CVSS3