CVE-2021-41817
Severity
7.5HIGH
EPSS
0.5%
top 34.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 1
Latest updateJan 18
Description
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages8 packages
Also affects: Debian Linux 10.0, 11.0, 9.0, Fedora 34, 35, Linux Enterprise 12.0, 15.0, Enterprise Linux 7.0, 8.0
🔴Vulnerability Details
5📋Vendor Advisories
4Microsoft▶
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1 3.1.2 3.0.2 and 2.0.1.↗2022-01-11
Debian▶
CVE-2021-41817: ruby2.7 - Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expressi...↗2021
💬Community
1HackerOne
▶