Lucene search

K
cvelistMitreCVELIST:CVE-2023-28756
HistoryMar 31, 2023 - 12:00 a.m.

CVE-2023-28756

2023-03-3100:00:00
mitre
www.cve.org
2
redos
ruby
time
parser
invalid urls
execution time
fixed versions

6 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.5%

A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.