File tree 2 files changed +19
-0
lines changed
2 files changed +19
-0
lines changed Original file line number Diff line number Diff line change @@ -38,5 +38,6 @@ This database would not be possible without volunteers willing to submit pull re
38
38
* [ Brendan Coles] ( https://github.com/bcoles )
39
39
* [ Florian Wininger] ( https://github.com/fwininger )
40
40
* [ Al Snow] ( https://github.com/jasnow )
41
+ * [ Adrian Hirt] ( https://github.com/Adrian-Hirt )
41
42
42
43
The rubysec.com domain was graciously donated by [ Jordi Massaguer] ( https://github.com/jordimassaguerpla ) .
Original file line number Diff line number Diff line change
1
+ ---
2
+ gem : uri
3
+ cve : 2023-28755
4
+ ghsa : hv5j-3h9f-99c2
5
+ url : https://github.com/advisories/GHSA-hv5j-3h9f-99c2
6
+ date : 2023-03-31
7
+ title : Ruby URI component ReDoS issue
8
+ description : |
9
+ A ReDoS issue was discovered in the URI component through 0.12.0 in
10
+ Ruby through 3.2.1. The URI parser mishandles invalid URLs that have
11
+ specific characters. It causes an increase in execution time for parsing
12
+ strings to URI objects. The fixed versions are 0.12.1, 0.11.1,
13
+ 0.10.2 and 0.10.0.1.
14
+ patched_versions :
15
+ - ~> 0.10.0.1
16
+ - ~> 0.10.2
17
+ - ~> 0.11.1
18
+ - " >= 0.12.1"
You can’t perform that action at this time.
0 commit comments