7.5

CVE-2021-41817

Exploit
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ruby-lang ≫ Date SwPlatform ruby Version < 2.0.1
Ruby-lang ≫ Date SwPlatform ruby Version >= 3.0.0 < 3.0.2
Ruby-lang ≫ Date SwPlatform ruby Version >= 3.1.0 < 3.1.2
Ruby-lang ≫ Date Version 3.2.0 SwPlatform ruby
Ruby-lang ≫ Ruby Version >= 2.6.0 < 2.6.9
Ruby-lang ≫ Ruby Version >= 2.7.0 < 2.7.5
Ruby-lang ≫ Ruby Version >= 3.0.0 < 3.0.3
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Fedoraproject ≫ Fedora Version 34
Fedoraproject ≫ Fedora Version 35
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Suse ≫ Linux Enterprise Version 12.0
Suse ≫ Linux Enterprise Version 15.0
Opensuse ≫ Factory Version -
Opensuse ≫ Leap Version 15.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.22% 0.866
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-1333 Inefficient Regular Expression Complexity

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

https://security.gentoo.org/glsa/202401-27
https://hackerone.com/reports/1254844
Permissions Required
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IUXQCH6FRKANCVZO2Q7D2SQX33FP3KWN/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UTOJGS5IEFDK3UOO7IY4OTTFGHGLSWZF/
https://www.ruby-lang.org/en/news/2021/11/15/date-parsing-method-regexp-dos-cve-2021-41817/
Vendor Advisory
Exploit