Related Vulnerabilities: CVE-2021-41817  

In the Ruby "date" gem before versions 3.2.1, 3.1.2, 3.0.2, and 2.0.1, there is a regular expression denial of service vulnerability (ReDoS) on date parsing methods. An attacker can exploit this vulnerability to cause an effective denial of service attack.

Severity Low

Remote Yes

Type Denial of service

Description

In the Ruby "date" gem before versions 3.2.1, 3.1.2, 3.0.2, and 2.0.1, there is a regular expression denial of service vulnerability (ReDoS) on date parsing methods. An attacker can exploit this vulnerability to cause an effective denial of service attack.

AVG-2557 ruby2.6 2.6.8-2 Low Vulnerable

AVG-2556 ruby2.7 2.7.4-2 Low Vulnerable

AVG-2555 ruby 3.0.2-2 Low Vulnerable

https://www.ruby-lang.org/en/news/2021/11/15/date-parsing-method-regexp-dos-cve-2021-41817/