rubygem-uri: ReDoS vulnerability - upstream's incomplete fix for CVE-2023-28755
Published Jun 29, 2023
5.3
MEDIUMCVSS 3.1
EPSS 1.70%
Description
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.
Affected products
No data.
No data.
Red Hat Enterprise Linux 8
ruby:2.5-8100020240627152904.489197e6
Fixed · RHSA-2024:4499
Red Hat Enterprise Linux 8
ruby:3.1-8090020240311122605.a75119d5
Fixed · RHSA-2024:1431
Red Hat Enterprise Linux 9
ruby:3.1-9030020240320163942.9
Fixed · RHSA-2024:1576
Red Hat 3scale API Management Platform 2
3scale-amp-system-container
Will not fix
Red Hat Enterprise Linux 8
ruby:3.0/ruby
Will not fix
Red Hat Enterprise Linux 9
ruby
Will not fix
Red Hat Satellite 6
puppet-agent
Affected
Red Hat Satellite 6
ruby
Not affected
Red Hat Satellite 6
rubygem-bundler
Not affected
Red Hat Software Collections
rh-ruby30-ruby
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | ruby:2.5-8100020240627152904.489197e6 | Fixed | RHSA-2024:4499 |
| Red Hat Enterprise Linux 8 | ruby:3.1-8090020240311122605.a75119d5 | Fixed | RHSA-2024:1431 |
| Red Hat Enterprise Linux 9 | ruby:3.1-9030020240320163942.9 | Fixed | RHSA-2024:1576 |
| Red Hat 3scale API Management Platform 2 | 3scale-amp-system-container | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | ruby:3.0/ruby | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | ruby | Will not fix | n/a |
| Red Hat Satellite 6 | puppet-agent | Affected | n/a |
| Red Hat Satellite 6 | ruby | Not affected | n/a |
| Red Hat Satellite 6 | rubygem-bundler | Not affected | n/a |
| Red Hat Software Collections | rh-ruby30-ruby | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability exists due to an incomplete fix for CVE-2023-28755 in upstream.
References (21)
- https://access.redhat.com/security/cve/CVE-2023-36617 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2218614 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-1827 Advisory
- https://github.com/advisories/GHSA-hww2-5g85-429m Advisory
- https://github.com/ruby/uri/commit/05b1e7d026b886e65a60ee35625229da9ec220bb
- https://github.com/ruby/uri/commit/38bf797c488bcb4a37fb322bfa84977981863ec6
- https://github.com/ruby/uri/commit/3cd938df20db26c9439e9f681aadfb9bbeb6d1c0
- https://github.com/ruby/uri/commit/4d02315181d8a485496f1bb107a6ab51d6f3a35f
- https://github.com/ruby/uri/commit/70794abc162bb15bb934713b5669713d6700d35c
- https://github.com/ruby/uri/commit/7e33934c91b7f8f3ea7b7a4258b468e19f636bc3
- https://github.com/ruby/uri/commit/9a8e0cc03da964054c2a4ea26b59c53c3bae4921
- https://github.com/ruby/uri/commit/ba36c8a3ecad8c16dd3e60a6da9abd768206c8fa
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/uri/CVE-2023-36617.yml
- https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QA6XUKUY7B5OLNQBLHOT43UW7C5NIOQQ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF
- https://nvd.nist.gov/vuln/detail/CVE-2023-36617
- https://security.netapp.com/advisory/ntap-20230725-0002
- https://www.cve.org/CVERecord?id=CVE-2023-36617
- https://www.ruby-lang.org/en/news/2023/06/29/redos-in-uri-CVE-2023-36617 MitigationVendor Advisory
Change history (0)
No recorded changes yet.