CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS
Percentile
72.3%
A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.
Vendor | Product | Version | CPE |
---|---|---|---|
lambdaisland | uri | * | cpe:2.3:a:lambdaisland:uri:*:*:*:*:*:*:*:* |
lambdaisland | uri | 0.10.1 | cpe:2.3:a:lambdaisland:uri:0.10.1:*:*:*:*:*:*:* |
lambdaisland | uri | 0.11.0 | cpe:2.3:a:lambdaisland:uri:0.11.0:*:*:*:*:*:*:* |
lambdaisland | uri | 0.12.0 | cpe:2.3:a:lambdaisland:uri:0.12.0:*:*:*:*:*:*:* |
github.com/advisories/GHSA-hv5j-3h9f-99c2
github.com/ruby/uri/releases
github.com/rubysec/ruby-advisory-db/blob/master/gems/uri/CVE-2023-28755.yml
lists.debian.org/debian-lts-announce/2023/04/msg00033.html
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFZANOQA4RYX7XCB42OO3P24DQKWHEKA
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G76GZG3RAGYF4P75YY7J7TGYAU7Z5E2T
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QA6XUKUY7B5OLNQBLHOT43UW7C5NIOQQ
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WMIOPLBAAM3FEQNAXA2L7BDKOGSVUT5Z
lists.fedoraproject.org/archives/list/[email protected]/message/FFZANOQA4RYX7XCB42OO3P24DQKWHEKA
lists.fedoraproject.org/archives/list/[email protected]/message/G76GZG3RAGYF4P75YY7J7TGYAU7Z5E2T
lists.fedoraproject.org/archives/list/[email protected]/message/WMIOPLBAAM3FEQNAXA2L7BDKOGSVUT5Z
nvd.nist.gov/vuln/detail/CVE-2023-28755
security.gentoo.org/glsa/202401-27
security.netapp.com/advisory/ntap-20230526-0003
www.ruby-lang.org/en/downloads/releases
www.ruby-lang.org/en/news/2022/12/25/ruby-3-2-0-released
www.ruby-lang.org/en/news/2023/03/28/redos-in-uri-cve-2023-28755