Description
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
Remediation
References
Related Vulnerabilities
Apache Traffic Server CVE-2023-30631 Vulnerability (CVE-2023-30631)
Grafana Other Vulnerability (CVE-2021-28147)
Joomla! Core 1.0.x Multiple Vulnerabilities (1.0.0 - 1.0.9)
WordPress 4.0.x Multiple Vulnerabilities (4.0 - 4.0.18)
Jenkins Use of Insufficiently Random Values Vulnerability (CVE-2020-2099)