Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-36617

Опубликовано: 29 июн. 2023
Источник: redhat
CVSS3: 5.3

Описание

A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.

A flaw was found in the rubygem URI. The URI parser mishandles invalid URLs that have specific characters, which causes an increase in execution time parsing strings to URI objects. This issue may result in a regular expression denial of service (ReDoS).

Отчет

This vulnerability exists due to an incomplete fix for CVE-2023-28755 in upstream.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp-system-containerWill not fix
Red Hat Enterprise Linux 8ruby:3.0/rubyWill not fix
Red Hat Enterprise Linux 9rubyWill not fix
Red Hat Satellite 6puppet-agentAffected
Red Hat Satellite 6rubyNot affected
Red Hat Satellite 6rubygem-bundlerNot affected
Red Hat Software Collectionsrh-ruby30-rubyWill not fix
Red Hat Enterprise Linux 8rubyFixedRHSA-2024:143119.03.2024
Red Hat Enterprise Linux 8rubyFixedRHSA-2024:449911.07.2024
Red Hat Enterprise Linux 9rubyFixedRHSA-2024:157601.04.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-185
https://bugzilla.redhat.com/show_bug.cgi?id=2218614rubygem-uri: ReDoS vulnerability - upstream's incomplete fix for CVE-2023-28755

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 2 года назад

A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.

CVSS3: 5.3
nvd
почти 2 года назад

A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.

CVSS3: 5.3
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 5.3
debian
почти 2 года назад

A ReDoS issue was discovered in the URI component before 0.12.2 for Ru ...

CVSS3: 5.3
github
почти 2 года назад

URI gem has ReDoS vulnerability

5.3 Medium

CVSS3