7.5

CVE-2021-4250

Exploit

cgriego active_attr Regex boolean_typecaster.rb call denial of service

A vulnerability classified as problematic has been found in cgriego active_attr up to 0.15.2. This affects the function call of the file lib/active_attr/typecasting/boolean_typecaster.rb of the component Regex Handler. The manipulation of the argument value leads to denial of service. The exploit has been disclosed to the public and may be used. Upgrading to version 0.15.3 is able to address this issue. The name of the patch is dab95e5843b01525444b82bd7b336ef1d79377df. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216207.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Active Attr ProjectActive Attr Version < 0.15.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.11% 0.615
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cna@vuldb.com 3.5 2.1 1.4
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CWE-404 Improper Resource Shutdown or Release

The product does not release or incorrectly releases a resource before it is made available for re-use.

https://github.com/cgriego/active_attr/commit/dab95e5843b01525444b82bd7b336ef1d79377df
Patch
Third Party Advisory
https://github.com/cgriego/active_attr/issues/184
Patch
Third Party Advisory
Exploit
Issue Tracking
https://github.com/cgriego/active_attr/pull/185
Patch
Third Party Advisory
https://github.com/cgriego/active_attr/releases/tag/v0.15.3
Third Party Advisory
Release Notes
https://vuldb.com/?id.216207
Third Party Advisory