Debian Ruby3.1 vulnerabilities
22 known vulnerabilities affecting debian/ruby3.1.
Total CVEs
22
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM14LOW4
Vulnerabilities
Page 2 of 2
CVE-2023-36617LOWCVSS 5.3fixed in ruby2.7 2.7.4-1+deb11u2 (bullseye)2023
CVE-2023-36617 [MEDIUM] CVE-2023-36617: jruby - A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The UR...
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed v
debian
CVE-2021-33621HIGHCVSS 8.8fixed in ruby2.7 2.7.4-1+deb11u2 (bullseye)2021
CVE-2021-33621 [HIGH] CVE-2021-33621: ruby2.7 - The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby ...
The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.
Scope: local
bullseye: resolved (fixed in 2.7.4-1+deb11u2)
debian
← Previous2 / 2