CVE-2017-0900: Input Validation
Last updated 24 July 2024
Other sources
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a query command.
Upstream patch:
https://github.com/rubygems/rubygems/commit/8a38a4fc24c6591e6c8f43d1fadab6efeb4d6251
Bug report:
https://hackerone.com/reports/243003
External References:
http://blog.rubygems.org/2017/08/27/2.6.13-released.html
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-0900?
CVE-2017-0900 refers to a vulnerability in RubyGems version 2.6.12 and earlier that allows maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients.
What is the severity of CVE-2017-0900?
The severity of CVE-2017-0900 is high, with a CVSS base score of 7.5.
Which software versions are affected by CVE-2017-0900?
RubyGems version 2.6.12 and earlier is affected by CVE-2017-0900.
How can I fix CVE-2017-0900?
To fix CVE-2017-0900, you should upgrade to RubyGems version 2.6.13 or later.
Where can I find more information about CVE-2017-0900?
You can find more information about CVE-2017-0900 on the official RubyGems blog and GitHub repository, as well as on HackerOne.