Vulnerability Description
A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rubyonrails | Globalid | >= 0.2.1, < 1.0.1 |
Related Weaknesses (CWE)
References
- https://discuss.rubyonrails.org/t/cve-2023-22799-possible-redos-based-dos-vulnerPatchVendor Advisory
- https://discuss.rubyonrails.org/t/cve-2023-22799-possible-redos-based-dos-vulnerPatchVendor Advisory
FAQ
What is CVE-2023-22799?
CVE-2023-22799 is a vulnerability with a CVSS score of 7.5 (HIGH). A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. A...
How severe is CVE-2023-22799?
CVE-2023-22799 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-22799?
Check the references section above for vendor advisories and patch information. Affected products include: Rubyonrails Globalid.