Lucene search

K
cvelistHackeroneCVELIST:CVE-2023-22799
HistoryFeb 09, 2023 - 12:00 a.m.

CVE-2023-22799

2023-02-0900:00:00
CWE-400
hackerone
www.cve.org
4
redos vulnerability
dos
globalid
upgrade
workaround

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

39.0%

A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "https://github.com/rails/globalid",
    "versions": [
      {
        "version": "1.0.1",
        "status": "affected"
      }
    ]
  }
]

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

39.0%