CVE-2023-22796
published 2023-02-09CVE-2023-22796: A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed to the underscore method can cause the…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.71%
75.0th percentile
A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed to the underscore method can cause the regular expression engine to enter a state of catastrophic backtracking. This can cause the process to use large amounts of CPU and memory, leading to a possible DoS vulnerability.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| activesupport_project | activesupport | < 6.1.7.1 | 6.1.7.1 |
| activesupport_project | activesupport | >= 0 < 6.1.7.1 | 6.1.7.1 |
| activesupport_project | activesupport | >= 7.0.0 < 7.0.4.1 | 7.0.4.1 |
| activesupport_project | activesupport | >= 7.0.0 < 7.0.4.1 | 7.0.4.1 |
| debian | rails | < rails 2:6.1.7.3+dfsg-1 (bookworm) | rails 2:6.1.7.3+dfsg-1 (bookworm) |
| https | github.com_rails_rails | — | — |
| rubyonrails | rails | >= 0 < 2:6.0.3.7+dfsg-2+deb11u1 | 2:6.0.3.7+dfsg-2+deb11u1 |
| rubyonrails | rails | >= 0 < 2:6.1.7.3+dfsg-1 | 2:6.1.7.3+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:6.1.7.3+dfsg-1 | 2:6.1.7.3+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:6.1.7.3+dfsg-1 | 2:6.1.7.3+dfsg-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-22796: A regular expression based DoS vulnerability in Active Support <6
osv·2023-02-09·CVSS 7.5
CVE-2023-22796 [HIGH] CVE-2023-22796: A regular expression based DoS vulnerability in Active Support <6
A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed to the underscore method can cause the regular expression engine to enter a state of catastrophic backtracking. This can cause the process to use large amounts of CPU and memory, leading to a possible DoS vulnerability.
OSV
ReDoS based DoS vulnerability in Active Support's underscore
osv·2023-01-18·CVSS 7.5
CVE-2023-22796 [HIGH] ReDoS based DoS vulnerability in Active Support's underscore
ReDoS based DoS vulnerability in Active Support's underscore
There is a possible regular expression based DoS vulnerability in Active Support. This vulnerability has been assigned the CVE identifier CVE-2023-22796.
Versions Affected: All Not affected: None Fixed Versions: 5.2.8.15 (Rails LTS, which is a paid service and not part of the rubygem), 6.1.7.1, 7.0.4.1
Impact
A specially crafted string passed to the underscore method can cause the regular expression engine to enter a state of catastrophic backtracking. This can cause the process to use large amounts of CPU and memory, leading to a possible DoS vulnerability.
This affects String#underscore, ActiveSupport::Inflector.underscore, String#titleize, and any other methods using these.
All users running an affected release should eit
GHSA
ReDoS based DoS vulnerability in Active Support's underscore
ghsa·2023-01-18·CVSS 7.5
CVE-2023-22796 [HIGH] CWE-1333 ReDoS based DoS vulnerability in Active Support's underscore
ReDoS based DoS vulnerability in Active Support's underscore
There is a possible regular expression based DoS vulnerability in Active Support. This vulnerability has been assigned the CVE identifier CVE-2023-22796.
Versions Affected: All Not affected: None Fixed Versions: 5.2.8.15 (Rails LTS, which is a paid service and not part of the rubygem), 6.1.7.1, 7.0.4.1
Impact
A specially crafted string passed to the underscore method can cause the regular expression engine to enter a state of catastrophic backtracking. This can cause the process to use large amounts of CPU and memory, leading to a possible DoS vulnerability.
This affects String#underscore, ActiveSupport::Inflector.underscore, String#titleize, and any other methods using these.
All users running an affected release should eit
Red Hat
rubygem-activesupport: Regular Expression Denial of Service
vendor_redhat·2023-01-20·CVSS 7.5
CVE-2023-22796 [HIGH] CWE-1333 rubygem-activesupport: Regular Expression Denial of Service
rubygem-activesupport: Regular Expression Denial of Service
A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed to the underscore method can cause the regular expression engine to enter a state of catastrophic backtracking. This can cause the process to use large amounts of CPU and memory, leading to a possible DoS vulnerability.
A flaw was found in rubygem-activesupport. RubyGem's activesupport gem is vulnerable to a denial of service caused by a regular expression denial of service (ReDoS) flaw in Inflector.underscore. By sending a specially-crafted regex input, a remote attacker can use large amounts of CPU and memory, resulting in a denial of service.
Package: 3scale-amp-backend-container (Red Hat 3scale API Managem
Debian
CVE-2023-22796: rails - A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0...
vendor_debian·2023·CVSS 7.5
CVE-2023-22796 [HIGH] CVE-2023-22796: rails - A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0...
A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed to the underscore method can cause the regular expression engine to enter a state of catastrophic backtracking. This can cause the process to use large amounts of CPU and memory, leading to a possible DoS vulnerability.
Scope: local
bookworm: resolved (fixed in 2:6.1.7.3+dfsg-1)
bullseye: resolved (fixed in 2:6.0.3.7+dfsg-2+deb11u1)
forky: resolved (fixed in 2:6.1.7.3+dfsg-1)
sid: resolved (fixed in 2:6.1.7.3+dfsg-1)
trixie: resolved (fixed in 2:6.1.7.3+dfsg-1)
No detection rules found.
No public exploits indexed.
https://discuss.rubyonrails.org/t/cve-2023-22796-possible-redos-based-dos-vulnerability-in-active-supports-underscore/82116https://security.netapp.com/advisory/ntap-20240202-0009/https://www.debian.org/security/2023/dsa-5372https://discuss.rubyonrails.org/t/cve-2023-22796-possible-redos-based-dos-vulnerability-in-active-supports-underscore/82116https://security.netapp.com/advisory/ntap-20240202-0009/https://www.debian.org/security/2023/dsa-5372
2023-02-09
Published