Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38996
HistoryJan 25, 2023 - 1:30 a.m.

Regular Expression Denial Of Service (ReDoS)

2023-01-2501:30:39
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
actionpack
redos
vulnerability
cache.rb
ruby 3.2.0

EPSS

0.027

Percentile

90.6%

actionpack is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability exists in the if_none_match_etags function of cache.rb due to inefficient regular expression complexity which allows an attacker to crash the application. The vulnerability only applies to ruby < 3.2.0.