REDHAT-BUG-2349696: Medium severity Ruby CGI gem vulnerability
Published Mar 4, 2025
·Updated
In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.
Affected Software
1 affected component
Ruby CGI gem<0.4.2
Event History
Mar 4, 2025
Data Sourced
via Red Hat·12:01 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2349696?
The severity of REDHAT-BUG-2349696 is classified as a Regular Expression Denial of Service (ReDoS) vulnerability.
2
How do I fix REDHAT-BUG-2349696?
To fix REDHAT-BUG-2349696, upgrade the Ruby CGI gem to version 0.4.2 or later.
3
What versions are affected by REDHAT-BUG-2349696?
Versions of the Ruby CGI gem prior to 0.4.2 are affected by REDHAT-BUG-2349696.
4
What component is vulnerable in REDHAT-BUG-2349696?
The vulnerable component in REDHAT-BUG-2349696 is the Util#escapeElement method in the CGI gem.
5
Is REDHAT-BUG-2349696 a critical vulnerability?
While REDHAT-BUG-2349696 is not classified as critical, it poses a risk of Denial of Service if exploited.