cbcvebase.
CVE-2021-41817
published 2022-01-01

CVE-2021-41817: Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.

Affected

23 ranges
VendorProductVersion rangeFixed in
date_projectdate>= 0 < 2.0.12.0.1
date_projectdate>= 3.0.0 < 3.0.23.0.2
date_projectdate>= 3.1.0 < 3.1.23.1.2
date_projectdate>= 3.2.0 < 3.2.13.2.1
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianruby2.7< ruby2.7 2.7.4-1+deb11u1 (bullseye)ruby2.7 2.7.4-1+deb11u1 (bullseye)
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_ruby_3.1.2-2_on_cbl_mariner_2.0
opensuseleap
redhatenterprise_linux
redhatenterprise_linux
ruby-langdate< 2.0.12.0.1
ruby-langdate
ruby-langdate>= 3.0.0 < 3.0.23.0.2
ruby-langdate>= 3.1.0 < 3.1.23.1.2
ruby-langruby>= 2.6.0 < 2.6.92.6.9
ruby-langruby>= 2.7.0 < 2.7.52.7.5
ruby-langruby>= 3.0.0 < 3.0.33.0.3
suselinux_enterprise
suselinux_enterprise

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv9.8CRITICAL