Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-32740
HistoryJul 06, 2021 - 12:00 a.m.

CVE-2021-32740

2021-07-0600:00:00
ubuntu.com
ubuntu.com
23

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.003 Low

EPSS

Percentile

65.3%

Addressable is an alternative implementation to the URI implementation that
is part of Ruby’s standard library. An uncontrolled resource consumption
vulnerability exists after version 2.3.0 through version 2.7.0. Within the
URI template implementation in Addressable, a maliciously crafted template
may result in uncontrolled resource consumption, leading to denial of
service when matched against a URI. In typical usage, templates would not
normally be read from untrusted user input, but nonetheless, no previous
security advisory for Addressable has cautioned against doing this. Users
of the parsing capabilities in Addressable but not the URI template
capabilities are unaffected. The vulnerability is patched in version 2.8.0.
As a workaround, only create Template objects from trusted sources that
have been validated not to produce catastrophic backtracking.

Bugs

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.003 Low

EPSS

Percentile

65.3%