A ReDoS issue was discovered in the URI component. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The uri gem version 0.12.0, 0.11.0, 0.10.1, 0.10.0 and all versions prior 0.10.0 are vulnerable for this vulnerability.
Created ruby tracking bugs for this issue: Affects: fedora-all [bug 2186603] Created ruby:3.0/ruby tracking bugs for this issue: Affects: fedora-all [bug 2186604]
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2023-28755
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Via RHSA-2023:3291 https://access.redhat.com/errata/RHSA-2023:3291
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:3821 https://access.redhat.com/errata/RHSA-2023:3821
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:7025 https://access.redhat.com/errata/RHSA-2023:7025
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:1431 https://access.redhat.com/errata/RHSA-2024:1431
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:1576 https://access.redhat.com/errata/RHSA-2024:1576