Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40040
HistoryApr 04, 2023 - 2:02 p.m.

Regular Expression Denial Of Service (ReDoS)

2023-04-0414:02:35
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
regular expression denial of service
time.rb
insecure regex pattern
crash the application
invalid time
software

0.003 Low

EPSS

Percentile

69.5%

time is vulnerable to Regular Expression Denial Of Service (ReDoS). The vulnerability exists due to the insecure Regex pattern used in the rfc2822 function of time.rb, which allows an attacker to crash the application by providing an invalid time.

References