Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:18922
HistoryMay 16, 2019 - 2:16 a.m.

Denial Of Service (DoS)

2019-05-1602:16:34
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

EPSS

0.023

Percentile

89.7%

RubyGems is vulnerable to denial of service attacks. A local attacker can supply a specially crafted ‘query’ command to cause denial of service conditions by excessive CPU usage while parsing a sufficiently long gem summary. Query Command Handler is the affected component.