Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-2853-1 | ruby2.3 security update |
![]() |
DSA-5066-1 | ruby2.5 security update |
![]() |
DSA-5067-1 | ruby2.7 security update |
![]() |
GHSA-qg54-694p-wgpp | Regular expression denial of service vulnerability (ReDoS) in date |
![]() |
USN-5235-1 | Ruby vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T03:22:24.342Z
Reserved: 2021-09-29T00:00:00
Link: CVE-2021-41817

No data.

Status : Modified
Published: 2022-01-01T05:15:08.197
Modified: 2024-11-21T06:26:48.700
Link: CVE-2021-41817


No data.