cbcvebase.

Debian Jruby vulnerabilities

27 known vulnerabilities affecting debian/jruby.

Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH13MEDIUM11LOW2

Vulnerabilities

Page 2 of 2
CVE-2023-28755P4MEDIUMCVSS 5.3fixed in jruby 9.4.5.0+ds-1 (forky)2023
CVE-2023-28755 [MEDIUM] CVE-2023-28755: jruby - A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through... A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1. Scope: local bookworm: open forky: resolved (fixed in 9.4.5.0+ds-1) sid: r
debian
CVE-2018-1000078P4MEDIUMCVSS 6.1fixed in jruby 9.1.17.0-1 (bookworm)2018
CVE-2018-1000078 [MEDIUM] CVE-2018-1000078: jruby - RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and ... RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Cross Site Scripting (XSS) vulnerability in gem server display of homepage attribute that can result in XSS. This attack appear to be exploitable via the victim m
debian
CVE-2023-28756P4MEDIUMCVSS 5.3fixed in jruby 9.4.5.0+ds-1 (forky)2023
CVE-2023-28756 [MEDIUM] CVE-2023-28756: jruby - A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through... A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2. Scope: local bookworm: open forky: resolved (fixed in 9.4.5.0+ds-1) sid: resolved (fixed in
debian
CVE-2023-36617P4LOWCVSS 5.3fixed in ruby2.7 2.7.4-1+deb11u2 (bullseye)2023
CVE-2023-36617 [MEDIUM] CVE-2023-36617: jruby - A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The UR... A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed v
debian
CVE-2011-4838P4LOWCVSS 5.0fixed in jruby 1.5.6-4 (bookworm)2011
CVE-2011-4838 [MEDIUM] CVE-2011-4838: jruby - JRuby before 1.6.5.1 computes hash values without restricting the ability to tri... JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. Scope: local bookworm: resolved (fixed in 1.5.6-4) forky: resolved (fixed in 1.5.6-4) sid: resolved (fi
debian
CVE-2012-5370P4MEDIUMCVSS 5.0fixed in jruby 1.5.6-5 (bookworm)2012
CVE-2012-5370 [MEDIUM] CVE-2012-5370: jruby - JRuby computes hash values without properly restricting the ability to trigger h... JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against the MurmurHash2 algorithm, a different vulnerabi
debian
CVE-2010-1330P4MEDIUMCVSS 4.3fixed in jruby 1.5.0~rc1-1 (bookworm)2010
CVE-2010-1330 [MEDIUM] CVE-2010-1330: jruby - The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', ... The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string. Scope: local bookworm: resolved (fixed in 1.5.0~rc1-1) forky: resolved (fixed in 1.5.0~rc1-1) sid: resolved (fixed in 1
debian
Debian Jruby vulnerabilities | cvebase