Bug 1979702 (CVE-2021-32740)
Summary: | CVE-2021-32740 rubygem-addressable: ReDoS in templates | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Guilherme de Almeida Suckevicz <gsuckevi> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | aboyko, akarol, amackenz, amasferr, aos-bugs, bbuckingham, bcourt, bkearney, bmontgom, bnhassin, boliveir, btotty, chazlett, dbecker, dmetzger, drieden, ehelms, eparis, ewolinet, gmccullo, gtanzill, jburrell, jcantril, jhardy, jjoyce, jokerman, jschluet, jsherril, kaycoth, lhh, lpeer, lzap, mburns, mhulan, mkudlej, mmccune, mo, myarboro, nmoumoul, nstielau, obarenbo, orabin, pcreech, pdrozd, pjindal, pskopek, rchan, rjerrido, roliveri, sclewis, shawn.starr, simaishi, slinaber, smallamp, sokeeffe, sponnaga, sthorger, tdawson, tjochec, vondruch |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | addressable 2.8.0 | Doc Type: | If docs needed, set a value |
Doc Text: |
A resource-consumption vulnerability was found in rubygem addressable, where its URI template implementation could allow an attacker's crafted template to consume resources, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2021-11-01 01:49:01 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1982122, 1979703, 1979704, 1980197, 1980283, 1980946 | ||
Bug Blocks: | 1979706, 1997390 |
Description
Guilherme de Almeida Suckevicz
2021-07-06 18:50:48 UTC
Created rubygem-addressable tracking bugs for this issue: Affects: epel-7 [bug 1979704] Affects: fedora-all [bug 1979703] This issue has been addressed in the following products: Red Hat Satellite 6.10 for RHEL 7 Via RHSA-2021:4702 https://access.redhat.com/errata/RHSA-2021:4702 |