Lucene search

K
redhatcveRedhat.comRH:CVE-2023-28756
HistoryApr 03, 2023 - 2:43 p.m.

CVE-2023-28756

2023-04-0314:43:40
redhat.com
access.redhat.com
13
ruby
time parser
redos
time library
cve-2023-28756
regular expression

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

5.6 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.5%

A flaw was found in the Time gem and Time library of Ruby. The Time parser mishandles invalid strings with specific characters and causes an increase in execution time for parsing strings to Time objects. This issue may result in a Regular expression denial of service (ReDoS).

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

5.6 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.5%