CVE-2023-31606

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-31606
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-31606.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-31606
Aliases
Related
Published
2023-06-06T17:15:14Z
Modified
2024-10-12T10:54:25.134791Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A Regular Expression Denial of Service (ReDoS) issue was discovered in the sanitize_html function of redcloth gem v4.0.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

References

Affected packages

Debian:11 / ruby-redcloth

Package

Name
ruby-redcloth
Purl
pkg:deb/debian/ruby-redcloth?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.3.2-3
4.3.2-4
4.3.3-1
4.3.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / ruby-redcloth

Package

Name
ruby-redcloth
Purl
pkg:deb/debian/ruby-redcloth?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.3.2-4
4.3.3-1
4.3.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / ruby-redcloth

Package

Name
ruby-redcloth
Purl
pkg:deb/debian/ruby-redcloth?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.3-1

Affected versions

4.*

4.3.2-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/jgarber/redcloth

Affected ranges

Type
GIT
Repo
https://github.com/jgarber/redcloth
Events

Affected versions

Other

RELEASE_4_0_0
RELEASE_4_0_1
RELEASE_4_0_2
RELEASE_4_0_3
RELEASE_4_0_4
RELEASE_4_1_0
RELEASE_4_1_1
RELEASE_4_1_9
RELEASE_4_2_0
RELEASE_4_2_1
RELEASE_4_2_2
RELEASE_4_2_3

v4.*

v4.2.4
v4.2.4.pre
v4.2.4.pre1
v4.2.4.pre2
v4.2.4.pre3
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2