Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2853-1 | ruby2.3 security update |
Debian DSA |
DSA-5066-1 | ruby2.5 security update |
Debian DSA |
DSA-5067-1 | ruby2.7 security update |
Github GHSA |
GHSA-qg54-694p-wgpp | Regular expression denial of service vulnerability (ReDoS) in date |
Ubuntu USN |
USN-5235-1 | Ruby vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T03:22:24.342Z
Reserved: 2021-09-29T00:00:00
Link: CVE-2021-41817
No data.
Status : Modified
Published: 2022-01-01T05:15:08.197
Modified: 2024-11-21T06:26:48.700
Link: CVE-2021-41817
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Github GHSA
Ubuntu USN