Asymmetric denial of service - ReDoS In uri
Description
Ruby URI component ReDoS issue A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
alpine v3.18 | 3.1.4-r0 | ||
alpine v3.16 | 3.1.4-r0 | ||
alpine v3.21 | 3.1.4-r0 | ||
alpine v3.22 | 3.1.4-r0 | ||
alpine v3.15 | 3.0.6-r0 | ||
debian 14 | 3.4.20-1 | ||
rubygems | 0.12.1, 0.11.1, 0.10.2, 0.10.0.1 | ||
alpine v3.14 | 2.7.8-r0 | ||
alpine v3.19 | 3.1.4-r0 | ||
alpine v3.20 | 3.1.4-r0 |
1-10 of 23
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15.