Description
A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.
Remediation
References
Related Vulnerabilities
phpMyFAQ Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-15731)
MySQL CVE-2024-21047 Vulnerability (CVE-2024-21047)
Atlassian Confluence Missing Authorization Vulnerability (CVE-2021-26085)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2019-3894)
phpMyAdmin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-1149)