Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-27219

Опубликовано: 03 мар. 2025
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.

A flaw was found in Ruby's CGI gem. Processing specially crafted large cookies with the CGI::Cookie.parse method can cause excessive resource consumption due to a missing limit on the length of the raw cookie value, resulting in a denial of service.

Отчет

This issue will cause an excessive resource consumption, potentially resulting in a bad application performance. However, an attacker does have the ability to completely deny service to legitimate users. For this reason, this vulnerability has been rated with a moderate severity.

Меры по смягчению последствий

Do not process large cookies or strings with the CGI::Cookie.parse method from the CGI library. Adding a check to verify and limit the length of the cookie or string before processing it will mitigate this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6rubyOut of support scope
Red Hat Enterprise Linux 7rubyOut of support scope
Red Hat Enterprise Linux 8ruby:2.5/rubyOut of support scope
Red Hat Enterprise Linux 10rubyFixedRHSA-2025:813126.05.2025
Red Hat Enterprise Linux 8rubyFixedRHSA-2025:1021702.07.2025
Red Hat Enterprise Linux 8rubyFixedRHSA-2025:406323.04.2025
Red Hat Enterprise Linux 9rubyFixedRHSA-2025:448706.05.2025
Red Hat Enterprise Linux 9rubyFixedRHSA-2025:448806.05.2025
Red Hat Enterprise Linux 9rubyFixedRHSA-2025:449306.05.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2349699CGI: Denial of Service in CGI::Cookie.parse

EPSS

Процентиль: 73%
0.00778
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.8
ubuntu
около 1 года назад

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.

CVSS3: 5.8
nvd
около 1 года назад

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.

CVSS3: 5.3
msrc
около 1 года назад

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.

CVSS3: 5.8
debian
около 1 года назад

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in ...

CVSS3: 5.8
github
около 1 года назад

CGI has Denial of Service (DoS) potential in Cookie.parse

EPSS

Процентиль: 73%
0.00778
Низкий

5.3 Medium

CVSS3