Ruby CGI
cpe:2.3:a:ruby-lang:cgi:*:*:*:*:ruby:*:*
- < 0.4.2
A denial-of-service vulnerability has been identified in the CGI gem for Ruby, affecting versions prior to 0.4.2. The issue arises in the CGI::Cookie.parse method, which lacks a limit on the length of raw cookie values it processes. This oversight can lead to excessive resource consumption when handling extremely large cookies.
Exploitation of this vulnerability can cause excessive resource consumption, potentially leading to a denial-of-service condition.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.