Back

HIGH

rubygem-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser

Published Jun 2, 2020

Description

websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.

Affected products

Remediation

Red Hat statement

Red Hat CloudForms 4.7 (CFME 5.10) is in the maintenance phase and we will not be fixing Medium/Low impact security bugs. Reference: https://access.redhat.com/support/policy/updates/cloudforms Red Hat Satellite 6 ships affected RubyGem Websocket-extensions, however, product is not vulnerable to the flaw. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification

References (13)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner snyk
Published Jun 2, 2020
Updated Aug 4, 2024
Reserved Jan 21, 2020

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Important
Public date Jun 2, 2020
Bugzilla 1845978

ENISA EUVD

Assigner snyk
Published Jun 2, 2020
Updated Aug 4, 2024