CVE-2021-41817
Summary
| CVE | CVE-2021-41817 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-01 05:15:00 UTC |
| Updated | 2024-01-24 05:15:00 UTC |
| Description | Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 35 Update: ruby-3.0.4-153.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: ruby-3.0.4-153.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| HackerOne |
MISC |
hackerone.com |
|
| [SECURITY] Fedora 34 Update: ruby-3.0.4-153.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE-2021-41817: Regular Expression Denial of Service Vulnerability of Date Parsing Methods |
CONFIRM |
www.ruby-lang.org |
|
| Ruby: Multiple vulnerabilities (GLSA 202401-27) — Gentoo security |
|
security.gentoo.org |
|
| [SECURITY] Fedora 34 Update: ruby-3.0.4-153.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159635 Oracle Enterprise Linux Security Update for ruby:2.6 (ELSA-2022-0543)
- 160020 Oracle Enterprise Linux Security Update for ruby:2.5 (ELSA-2022-5779)
- 160091 Oracle Enterprise Linux Security Update for ruby:2.7 (ELSA-2022-6447)
- 160095 Oracle Enterprise Linux Security Update for ruby:3.0 (ELSA-2022-6450)
- 178965 Debian Security Update for ruby2.3 (DLA 2853-1)
- 179050 Debian Security Update for ruby2.7 (DSA 5067-1)
- 179051 Debian Security Update for ruby2.5 (DSA 5066-1)
- 198635 Ubuntu Security Notification for Ruby Vulnerabilities (USN-5235-1)
- 240090 Red Hat Update for ruby:2.6 (RHSA-2022:0544)
- 240092 Red Hat Update for ruby:2.6 (RHSA-2022:0543)
- 240116 Red Hat Update for rh-ruby26-ruby security (RHSA-2022:0708)
- 240156 Red Hat Update for ruby:2.6 (RHSA-2022:0582)
- 240571 Red Hat Update for ruby:2.5 (RHSA-2022:5779)
- 240659 Red Hat Update for ruby:3.0 security (RHSA-2022:6450)
- 240661 Red Hat Update for ruby:2.7 security (RHSA-2022:6447)
- 240720 Red Hat Update for rh-ruby27-ruby security (RHSA-2022:6856)
- 240723 Red Hat Update for rh-ruby30-ruby security (RHSA-2022:6855)
- 282660 Fedora Security Update for ruby (FEDORA-2022-82a9edac27)
- 282661 Fedora Security Update for ruby (FEDORA-2022-8cf0124add)
- 296062 Oracle Solaris 11.4 Support Repository Update (SRU) 43.113.3 Missing (CPUJAN2022)
- 356181 Amazon Linux Security Advisory for ruby : ALASRUBY3.0-2023-003
- 356252 Amazon Linux Security Advisory for ruby : ALASRUBY2.6-2023-002
- 356463 Amazon Linux Security Advisory for ruby : ALAS2RUBY3.0-2023-003
- 356731 Amazon Linux Security Advisory for ruby : ALAS2-2023-2345
- 500617 Alpine Linux Security Update for ruby
- 502024 Alpine Linux Security Update for ruby
- 504377 Alpine Linux Security Update for ruby
- 671873 EulerOS Security Update for ruby (EulerOS-SA-2022-1951)
- 690226 Free Berkeley Software Distribution (FreeBSD) Security Update for rubygem-date (6916ea94-4628-11ec-bbe2-0800270512f4)
- 710844 Gentoo Linux Ruby Multiple Vulnerabilities (GLSA 202401-27)
- 752103 SUSE Enterprise Linux Security Update for ruby2.5 (SUSE-SU-2022:1512-1)
- 755145 SUSE Enterprise Linux Security Update for ruby2.5 (SUSE-SU-2023:4176-1)
- 900505 Common Base Linux Mariner (CBL-Mariner) Security Update for ruby (7104)
- 901507 Common Base Linux Mariner (CBL-Mariner) Security Update for ruby (7110-1)
- 940455 AlmaLinux Security Update for ruby:2.6 (ALSA-2022:0543)
- 940614 AlmaLinux Security Update for ruby:2.5 (ALSA-2022:5779)
- 940657 AlmaLinux Security Update for ruby:2.7 (ALSA-2022:6447)
- 940849 AlmaLinux Security Update for ruby:3.0 (ALSA-2022:6450)
- 960464 Rocky Linux Security Update for ruby:2.5 (RLSA-2022:5779)
- 960588 Rocky Linux Security Update for ruby:2.7 (RLSA-2022:6447)
- 960814 Rocky Linux Security Update for ruby:2.6 (RLSA-2022:0543)