Ruby CGI
cpe:2.3:a:ruby-lang:cgi:*:*:*:*:ruby:*:*
- <= 0.3.5
- <= 0.3.6
- <= 0.4.0
- <= 0.4.1
A Regular Expression Denial-of-Service (ReDoS) vulnerability has been identified in the CGI gem for Ruby, specifically in versions prior to 0.4.2. The issue arises in the Util#escapeElement method, where a vulnerable regular expression can be exploited to cause high CPU consumption.
Exploitation of this vulnerability leads to increased CPU usage, causing a denial-of-service condition.
Users of the affected CGI gem versions should upgrade to version 0.3.5.1, 0.3.7, or 0.4.2 and later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.