CVE-2023-36617
published 2023-06-29CVE-2023-36617: A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.70%
74.8th percentile
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jruby | < ruby2.7 2.7.4-1+deb11u2 (bullseye) | ruby2.7 2.7.4-1+deb11u2 (bullseye) |
| debian | ruby2.7 | < ruby2.7 2.7.4-1+deb11u2 (bullseye) | ruby2.7 2.7.4-1+deb11u2 (bullseye) |
| debian | ruby3.1 | < ruby2.7 2.7.4-1+deb11u2 (bullseye) | ruby2.7 2.7.4-1+deb11u2 (bullseye) |
| debian | rubygems | < ruby2.7 2.7.4-1+deb11u2 (bullseye) | ruby2.7 2.7.4-1+deb11u2 (bullseye) |
| msrc | cbl2_ruby_3.1.4-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| ruby-lang | uri | < 0.10.3 | 0.10.3 |
| ruby-lang | uri | >= 0 < 0.10.0.3 | 0.10.0.3 |
| ruby-lang | uri | >= 0.10.1 < 0.10.3 | 0.10.3 |
| ruby-lang | uri | >= 0.11.0 < 0.12.2 | 0.12.2 |
| ruby-lang | uri | >= 0.11.0 < 0.11.2 | 0.11.2 |
| ruby-lang | uri | >= 0.12.0 < 0.12.2 | 0.12.2 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
ghsa5.3MEDIUM
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
RubyGems vulnerability
vendor_ubuntu·2025-09-15
CVE-2023-36617 RubyGems vulnerability
Title: RubyGems vulnerability
Summary: RubyGems could be made to consume resources if it received specially
crafted input.
It was discovered that RubyGems incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause RubyGems to
consume resources, leading to a regular expression denial of service
(ReDoS).
Instructions: In general, a standard system update will make all the necessary changes.
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Ubuntu
Ruby vulnerabilities
vendor_ubuntu·2023-07-12·CVSS 5.3
CVE-2023-36617 [MEDIUM] Ruby vulnerabilities
Title: Ruby vulnerabilities
Summary: Several security issues were fixed in Ruby.
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 20.10 and Ubuntu 20.04 LTS.
(CVE-2023-28755)
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
This issue exists because of an incomplete fix for CVE-2023-28755.
(CVE-2023-36617)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
rubygem-uri: ReDoS vulnerability - upstream's incomplete fix for CVE-2023-28755
vendor_redhat·2023-06-29·CVSS 5.3
CVE-2023-36617 [MEDIUM] CWE-185 rubygem-uri: ReDoS vulnerability - upstream's incomplete fix for CVE-2023-28755
rubygem-uri: ReDoS vulnerability - upstream's incomplete fix for CVE-2023-28755
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.
A flaw was found in the rubygem URI. The URI parser mishandles invalid URLs that have specific characters, which causes an increase in execution time parsing strings to URI objects. This issue may result in a regular expression denial of service (ReDoS).
Statement: This vulnerability exists due to an incomplete fix for CVE-2023-28755 in up
Microsoft
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strin
vendor_msrc·2023-06-13·CVSS 5.3
CVE-2023-36617 [MEDIUM] CWE-1333 A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strin
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in t
Debian
CVE-2023-36617: jruby - A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The UR...
vendor_debian·2023·CVSS 5.3
CVE-2023-36617 [MEDIUM] CVE-2023-36617: jruby - A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The UR...
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.
Scope: local
bookworm: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.1 vulnerabilities
osv·2023-07-12·CVSS 5.3
CVE-2023-28755 [MEDIUM] ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.1 vulnerabilities
ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.1 vulnerabilities
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 20.10 and Ubuntu 20.04 LTS.
(CVE-2023-28755)
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
This issue exists because of an incomplete fix for CVE-2023-28755.
(CVE-2023-36617)
OSV
URI gem has ReDoS vulnerability
osv·2023-06-29·CVSS 5.3
CVE-2023-36617 [MEDIUM] URI gem has ReDoS vulnerability
URI gem has ReDoS vulnerability
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with `rfc2396_parser.rb` and `rfc3986_parser.rb`.
NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.
[The Ruby advisory recommends](https://www.ruby-lang.org/en/news/2023/06/29/redos-in-uri-CVE-2023-36617/) updating the uri gem to 0.12.2. In order to ensure compatibility with the bundled version in older Ruby series, you may update as follows instead:
- For Ruby 3.0: Update to uri 0.10.3
- For Ruby 3.1 and 3.2: Update to uri 0.12.2.
You can use gem update uri to update it. If you
OSV
CVE-2023-36617: A ReDoS issue was discovered in the URI component before 0
osv·2023-06-29·CVSS 5.3
CVE-2023-36617 [MEDIUM] CVE-2023-36617: A ReDoS issue was discovered in the URI component before 0
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.
GHSA
URI gem has ReDoS vulnerability
ghsa·2023-06-29·CVSS 5.3
CVE-2023-36617 [MEDIUM] CWE-1333 URI gem has ReDoS vulnerability
URI gem has ReDoS vulnerability
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with `rfc2396_parser.rb` and `rfc3986_parser.rb`.
NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.
[The Ruby advisory recommends](https://www.ruby-lang.org/en/news/2023/06/29/redos-in-uri-CVE-2023-36617/) updating the uri gem to 0.12.2. In order to ensure compatibility with the bundled version in older Ruby series, you may update as follows instead:
- For Ruby 3.0: Update to uri 0.10.3
- For Ruby 3.1 and 3.2: Update to uri 0.12.2.
You can use gem update uri to update it. If you
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QA6XUKUY7B5OLNQBLHOT43UW7C5NIOQQ/https://security.netapp.com/advisory/ntap-20230725-0002/https://www.ruby-lang.org/en/news/2023/06/29/redos-in-uri-CVE-2023-36617/https://lists.debian.org/debian-lts-announce/2024/09/msg00000.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QA6XUKUY7B5OLNQBLHOT43UW7C5NIOQQ/https://lists.fedoraproject.org/archives/list/[email protected]/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/https://security.netapp.com/advisory/ntap-20230725-0002/https://www.ruby-lang.org/en/news/2023/06/29/redos-in-uri-CVE-2023-36617/
2023-06-29
Published