Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-36617


A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.


Published

2023-06-29T13:15:09.583

Last Modified

2024-11-21T08:10:04.680

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-1333

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ruby-lang uri < 0.10.3 Yes
Application ruby-lang uri < 0.12.2 Yes

References