First published: Tue Mar 21 2023(Updated: )
A flaw was found in the rubygem URI. The URI parser mishandles invalid URLs that have specific characters, which causes an increase in execution time parsing strings to URI objects. This may result in a regular expression denial of service (ReDoS).
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rh-ruby27-ruby | <0:2.7.8-132.el7 | 0:2.7.8-132.el7 |
rubygems/uri | <0.10.0.1 | 0.10.0.1 |
rubygems/uri | =0.10.1 | 0.10.2 |
rubygems/uri | =0.11.0 | 0.11.1 |
rubygems/uri | =0.12.0 | 0.12.1 |
debian/jruby | <=9.3.9.0+ds-8 | 9.4.8.0+ds-2 |
debian/ruby2.7 | <=2.7.4-1+deb11u1 | 2.7.4-1+deb11u4 |
debian/ruby3.1 | <=3.1.2-7+deb12u1<=3.1.2-8.5 | |
debian/rubygems | <=3.2.5-2<=3.3.15-2 | 3.6.3-1 |
ruby-lang URI Ruby | <=0.10.0 | |
ruby-lang URI Ruby | =0.10.1 | |
ruby-lang URI Ruby | =0.11.0 | |
ruby-lang URI Ruby | =0.12.0 | |
Debian | =10.0 | |
Fedora | =36 | |
Fedora | =37 | |
Fedora | =38 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.