Lucene search

K
nvd[email protected]NVD:CVE-2023-28755
HistoryMar 31, 2023 - 4:15 a.m.

CVE-2023-28755

2023-03-3104:15:09
CWE-1333
web.nvd.nist.gov
5
cve-2023-28755
redos
ruby
uri parser
execution time
parsing strings

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

7

Confidence

High

EPSS

0.004

Percentile

72.3%

A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.

Affected configurations

Nvd
Node
ruby-languriRange0.10.0ruby
OR
ruby-languriMatch0.10.1ruby
OR
ruby-languriMatch0.11.0ruby
OR
ruby-languriMatch0.12.0ruby
Node
debiandebian_linuxMatch10.0
OR
fedoraprojectfedoraMatch36
OR
fedoraprojectfedoraMatch37
OR
fedoraprojectfedoraMatch38
VendorProductVersionCPE
ruby-languri*cpe:2.3:a:ruby-lang:uri:*:*:*:*:*:ruby:*:*
ruby-languri0.10.1cpe:2.3:a:ruby-lang:uri:0.10.1:*:*:*:*:ruby:*:*
ruby-languri0.11.0cpe:2.3:a:ruby-lang:uri:0.11.0:*:*:*:*:ruby:*:*
ruby-languri0.12.0cpe:2.3:a:ruby-lang:uri:0.12.0:*:*:*:*:ruby:*:*
debiandebian_linux10.0cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
fedoraprojectfedora36cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
fedoraprojectfedora37cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
fedoraprojectfedora38cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

References

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

7

Confidence

High

EPSS

0.004

Percentile

72.3%