Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-36617
HistoryJun 29, 2023 - 1:15 p.m.

Design/Logic Flaw

2023-06-2913:15:00
PRIOn knowledge base
www.prio-n.com
13
redos
design flaw
logic flaw
uri component
parsing strings
cve-2023-28755
execution time increase
vulnerability
nvd

5.6 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.0%

A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.

CPENameOperatorVersion
urige0.11.0
urilt0.12.2
urilt0.10.3