First published: Tue Mar 21 2023(Updated: )
A flaw was found in the rubygem URI. The URI parser mishandles invalid URLs that have specific characters, which causes an increase in execution time parsing strings to URI objects. This may result in a regular expression denial of service (ReDoS).
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rh-ruby27-ruby | <0:2.7.8-132.el7 | 0:2.7.8-132.el7 |
Ruby-lang Uri | <=0.10.0 | |
Ruby-lang Uri | =0.10.1 | |
Ruby-lang Uri | =0.11.0 | |
Ruby-lang Uri | =0.12.0 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 | |
Fedoraproject Fedora | =38 | |
rubygems/uri | <0.10.0.1 | 0.10.0.1 |
rubygems/uri | =0.10.1 | 0.10.2 |
rubygems/uri | =0.11.0 | 0.11.1 |
rubygems/uri | =0.12.0 | 0.12.1 |
debian/jruby | <=9.3.9.0+ds-8 | 9.4.8.0+ds-1 |
debian/ruby2.7 | <=2.7.4-1+deb11u1 | 2.7.4-1+deb11u3 |
debian/ruby3.1 | <=3.1.2-7+deb12u1<=3.1.2-8.5 | |
debian/rubygems | <=3.2.5-2<=3.3.15-2 | 3.4.20-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.