Lack of data validation - Path Traversal In ruby
Description
An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
alpine v3.16 | 3.1.5-r0 | ||
alpine v3.17 | 3.1.5-r0 | ||
alpine v3.18 | 3.2.4-r0 | ||
alpine v3.19 | 3.2.4-r0 | ||
alpine v3.20 | 3.3.1-r0 | ||
alpine v3.21 | 3.3.1-r0 | ||
alpine v3.22 | 3.3.1-r0 | ||
debian 12 | 3.1.2-7+deb12u1 | ||
alpine v3.23 | 3.3.1-r0 | ||
rpm rhel9 | 0:3.0.7-162.el9_4 |
1-10 of 14
10
Aliases
1. 2. 3. 4. 5. 6. 7.