CVE-2021-41817 log

Source
Severity Low
Remote Yes
Type Denial of service
Description
A security issue has been found in Ruby before versions 3.0.3, 2.7.5 and 2.6.9. In the Ruby "date" gem before versions 3.2.1, 3.1.2, 3.0.2, and 2.0.1, there is a regular expression denial of service vulnerability (ReDoS) on date parsing methods. An attacker can exploit this vulnerability to cause an effective denial of service attack.
Group Package Affected Fixed Severity Status Ticket
AVG-2557 ruby2.6 2.6.8-2 Medium Unknown
AVG-2556 ruby2.7 2.7.4-2 2.7.5-1 Medium Fixed
AVG-2555 ruby 3.0.2-2 3.0.3-1 Medium Fixed
References
https://www.ruby-lang.org/en/news/2021/11/15/date-parsing-method-regexp-dos-cve-2021-41817/
https://www.ruby-lang.org/en/news/2021/11/24/ruby-3-0-3-released/
https://www.ruby-lang.org/en/news/2021/11/24/ruby-2-7-5-released/
https://www.ruby-lang.org/en/news/2021/11/24/ruby-2-6-9-released/
https://github.com/ruby/date/commit/3959accef8da5c128f8a8e2fd54e932a4fb253b0