Open Source
CVE-2023-28755: ReDoS vulnerability in URI
We have released the uri gem version 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1 that has a security fix for a ReDoS vulnerability.
This vulnerability has been assigned the CVE identifier CVE-2023-28755.
Details
A ReDoS issue was discovered in the URI component. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects.
The uri gem version 0.12.0, 0.11.0, 0.10.1, 0.10.0 and all versions prior 0.10.0 are vulnerable for this vulnerability.
Recommended action
We recommend to update the uri gem to 0.12.1. In order to ensure compatibility with bundled version in older Ruby series, you may update as follows instead:
- For Ruby 2.7: Update to
uri0.10.0.1 - For Ruby 3.0: Update to
uri0.10.2 - For Ruby 3.1: Update to
uri0.11.1 - For Ruby 3.2: Update to
uri0.12.1
You can use gem update uri to update it. If you are using bundler, please add gem "uri", ">= 0.12.1" (or other version mentioned above) to your Gemfile.
Affected versions
- uri gem 0.12.0
- uri gem 0.11.0
- uri gem 0.10.1
- uri gem 0.10.0 or before
Credits
Thanks to Dominic Couture for discovering this issue.
History
- Originally published at 2023-03-28 01:00:00 (UTC)
- Update Affected versions at 2023-03-28 02:00:00 (UTC)
Posted by hsbt on 28 Mar 2023
Automate container and pod deployments with Podman and Ansible
Podman and Ansible are even better together for enabling automation and orchestration of container and pod lifecycles. Read More at Enable Sysadmin
The post Automate container and pod deployments with Podman and Ansible appeared first on Linux.com.
Windows needs to stop showing tabloid news
Baš mi se svida – Domaćice sa Bosfora 6 Epizoda
Video by via Dailymotion Source Glumac/GlumicaSerhat TutumluerCeyda DüvenciÖzge ÖzderHale AkınlıBennu YıldırımlarBatuhan KaracakayaSongül ÖdenMelda AratCenk Ertanİlker Kurtİncilay ŞahinMetin BüktelEvrim SolmazServer MutluEce HakimDevrim ÖzderErdal BilingenFurkan Andıç Go to Source
Frente fria acaba com recorde de calor no Sul
Video by via Dailymotion Source A frente fria que ingressou no Rio Grande do Sul neste fim de semana acabou com sequência de dias de calor recorde na Grande Porto Alegre, sem precedente na climatologia de março nos últimos 40 anos na estação de referência histórica da área metropolitana, em Campo Bom, que possui dados … Read more
Classic Fortnite: Chapter 1 Season 5 Squad Win
Video by via Dailymotion Source Classic Fortnite: Chapter 1 Season 5 Squad Win Go to Source
Nasamsam na mga armas sa compound ni dating Gov. Teves, isinasailalim na sa forensic exam | 24 Oras
Video by via Dailymotion Source 24 Oras is GMA Network’s flagship newscast, anchored by Mike Enriquez, Mel Tiangco and Vicky Morales. It airs on GMA-7 Mondays to Fridays at 6:30 PM (PHL Time) and on weekends at 6:00 PM. For more videos from 24 Oras, visit http://www.gmanetwork.com/24oras. #Nakatutok24Oras Breaking news and stories from the Philippines … Read more
Turnover ng 1,380 housing units sa St. Gregory Homes Housing Project sa Malabon, pinangunahan ni…
Video by via Dailymotion Source Turnover ng 1,380 housing units sa St. Gregory Homes Housing Project sa Malabon, pinangunahan ni PBBM Go to Source
News & Views Live: सावरकरांचा वाद.. तरीही गांधींना ठाकरेंशिवाय पर्याय नाही..Thackeray | Rahul Gandhi
Video by via Dailymotion Source News & Views Live: सावरकरांचा वाद….तरीही गांधींना ठाकरेंशिवाय पर्याय नाही.. | Uddhav Thackeray | Rahul Gandhi | Veer Savarkar #uddhavthackeray #Rahulgandhi #maharashtranews #Lokmat Subscribe to Our Channel https://www.youtube.com/user/LokmatNews?sub_confirmation=1 आमचा video आवडल्यास धन्यवाद. Like, Share and Subscribe करायला विसरू नका! मित्रांसोबत गप्पा मारताना विश्वसनीय, संशोधनावर आधारीत माहिती सादर करायची असेल तर … Read more