Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-27219

Опубликовано: 04 мар. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.8

Описание

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.

РелизСтатусПримечание
devel

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/noble

needs-triage

esm-apps/xenial

needs-triage

esm-infra-legacy/trusty

needs-triage

focal

ignored

end of standard support, was needs-triage
jammy

DNE

noble

needs-triage

oracular

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

DNE

esm-infra/xenial

released

2.3.1-2~ubuntu16.04.16+esm10
focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

released

2.5.1-1ubuntu1.16+esm4
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

not-affected

2.7.0-5ubuntu1.18
focal

released

2.7.0-5ubuntu1.18
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

released

3.0.2-7ubuntu2.10
noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

released

3.2.3-1ubuntu0.24.04.5
oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

released

3.3.7-1ubuntu2
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

released

3.3.4-2ubuntu5.2
plucky

released

3.3.7-1ubuntu2
upstream

needs-triage

Показывать по

EPSS

Процентиль: 38%
0.00163
Низкий

5.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
4 месяца назад

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.

CVSS3: 5.8
nvd
4 месяца назад

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.

CVSS3: 7.5
msrc
3 месяца назад

Описание отсутствует

CVSS3: 5.8
debian
4 месяца назад

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in ...

CVSS3: 5.8
github
4 месяца назад

CGI has Denial of Service (DoS) potential in Cookie.parse

EPSS

Процентиль: 38%
0.00163
Низкий

5.8 Medium

CVSS3

Уязвимость CVE-2025-27219