NA

CVE-2023-22799

Published: 09/02/2023 Updated: 16/02/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rubyonrails globalid

Vendor Advisories

Debian Bug report logs - #1029851 ruby-globalid: CVE-2023-22799 Package: src:ruby-globalid; Maintainer for src:ruby-globalid is Debian Ruby Team &lt;pkg-ruby-extras-maintainers@listsaliothdebianorg&gt;; Reported by: Salvatore Bonaccorso &lt;carnil@debianorg&gt; Date: Sat, 28 Jan 2023 20:27:02 UTC Severity: important Tags: se ...
Description<!----> This CVE is under investigation by Red Hat Product Security ...