Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-28756
HistoryMar 31, 2023 - 12:00 a.m.

CVE-2023-28756

2023-03-3100:00:00
ubuntu.com
ubuntu.com
9
cve-2023-28756
redos
time component
ruby 3.2.1
url parsing
fixed versions
execution time
unix

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

0.003 Low

EPSS

Percentile

69.5%

A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby
through 3.2.1. The Time parser mishandles invalid URLs that have specific
characters. It causes an increase in execution time for parsing strings to
Time objects. The fixed versions are 0.1.1 and 0.2.2.

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

0.003 Low

EPSS

Percentile

69.5%