Skip to content

Commit

Permalink
security/vuxml: Document ReDoS vulnerability in rubygem-uri
Browse files Browse the repository at this point in the history
  • Loading branch information
Yasuhiro Kimura authored and Yasuhiro Kimura committed Mar 30, 2023
1 parent 000b96c commit 81860dd
Showing 1 changed file with 54 additions and 0 deletions.
54 changes: 54 additions & 0 deletions security/vuxml/vuln/2023.xml
@@ -1,3 +1,57 @@
<vuln vid="9b60bba1-cf18-11ed-bd44-080027f5fec9">
<topic>rubygem-uri -- ReDoS vulnerability</topic>
<affects>
<package>
<name>ruby</name>
<range><ge>2.7.0,1</ge><lt>2.7.8,1</lt></range>
<range><ge>3.0.0,1</ge><lt>3.0.6,1</lt></range>
<range><ge>3.1.0,1</ge><lt>3.1.4,1</lt></range>
<range><ge>3.2.0.p1,1</ge><lt>3.2.2,1</lt></range>
</package>
<package>
<name>ruby27</name>
<range><ge>2.7.0,1</ge><lt>2.7.8,1</lt></range>
</package>
<package>
<name>ruby30</name>
<range><ge>3.0.0,1</ge><lt>3.0.6,1</lt></range>
</package>
<package>
<name>ruby31</name>
<range><ge>3.1.0,1</ge><lt>3.1.4,1</lt></range>
</package>
<package>
<name>ruby32</name>
<range><ge>3.2.0.p1,1</ge><lt>3.2.2,1</lt></range>
</package>
<package>
<name>rubygem-uri</name>
<range><lt>0.12.1</lt></range>
</package>
</affects>
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
<p>Dominic Couture reports:</p>
<blockquote cite="https://www.ruby-lang.org/en/news/2023/03/28/redos-in-uri-cve-2023-28755/">
<p>
A ReDoS issue was discovered in the URI component. The URI
parser mishandles invalid URLs that have specific
characters. It causes an increase in execution time for
parsing strings to URI objects.
</p>
</blockquote>
</body>
</description>
<references>
<cvename>CVE-2023-28755</cvename>
<url>https://www.ruby-lang.org/en/news/2023/03/28/redos-in-uri-cve-2023-28755/</url>
</references>
<dates>
<discovery>2023-03-28</discovery>
<entry>2023-03-30</entry>
</dates>
</vuln>

<vuln vid="dc33795f-ced7-11ed-b1fe-6805ca2fa271">
<topic>powerdns-recursor -- denial of service</topic>
<affects>
Expand Down

0 comments on commit 81860dd

Please sign in to comment.