CVE-2023-36617
Summary
| CVE | CVE-2023-36617 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-29 13:15:00 UTC |
| Updated | 2023-07-25 15:15:00 UTC |
| Description | A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version. |
Risk And Classification
Problem Types: CWE-1333
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2023-36617 Ruby Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| CVE-2023-36617: ReDoS vulnerability in URI | MISC | www.ruby-lang.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161427 Oracle Enterprise Linux Security Update for ruby:3.1 (ELSA-2024-1431)
- 161454 Oracle Enterprise Linux Security Update for ruby:3.1 (ELSA-2024-1576)
- 199461 Ubuntu Security Notification for Ruby Vulnerabilities (USN-6219-1)
- 243097 Red Hat Update for ruby:3.1 security (RHSA-2024:1431)
- 243151 Red Hat Update for ruby:3.1 security (RHSA-2024:1576)
- 673375 EulerOS Security Update for ruby (EulerOS-SA-2023-2868)
- 673380 EulerOS Security Update for ruby (EulerOS-SA-2023-2800)
- 673861 EulerOS Security Update for ruby (EulerOS-SA-2023-2824)
- 673984 EulerOS Security Update for ruby (EulerOS-SA-2023-2851)
- 941625 AlmaLinux Security Update for ruby:3.1 (ALSA-2024:1431)
- 941633 AlmaLinux Security Update for ruby:3.1 (ALSA-2024:1576)
- 961138 Rocky Linux Security Update for ruby:3.1 (RLSA-2024:1431)
- 961149 Rocky Linux Security Update for ruby:3.1 (RLSA-2024:1576)