Описание
websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 0.1.2-1+deb9u1build0.18.04.1 |
devel | not-affected | 0.1.5-1 |
eoan | ignored | end of life |
esm-apps/bionic | released | 0.1.2-1+deb9u1build0.18.04.1 |
esm-apps/focal | released | 0.1.2-1+deb9u1build0.20.04.1 |
esm-apps/jammy | not-affected | 0.1.5-1 |
esm-apps/xenial | released | 0.1.2-1+deb9u1build0.16.04.1 |
esm-infra-legacy/trusty | DNE | |
focal | released | 0.1.2-1+deb9u1build0.20.04.1 |
groovy | ignored | end of life |
Показывать по
Ссылки на источники
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.
websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.
websocket-extensions ruby module prior to 0.1.5 allows Denial of Servi ...
5 Medium
CVSS2
7.5 High
CVSS3