CVE-2021-41817 is a Regular Expression Denial of Service (ReDoS) vulnerability affecting the Date.parse function in the Ruby date gem versions through 3.2.0, impacting various Linux distributions like Debian, Fedora, and Red Hat. This vulnerability carries a high CVSS score of 7.5, indicating a severe impact (denial of service) with low attack complexity and no user interaction required. While there is no evidence of active exploitation or publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.1CPE matchmatch criteria | cpe:2.3:a:ruby-lang:date:*:*:*:*:*:ruby:*:* | ||
>= 3.0.0, < 3.0.2CPE matchmatch criteria | cpe:2.3:a:ruby-lang:date:*:*:*:*:*:ruby:*:* | ||
>= 3.1.0, < 3.1.2CPE matchmatch criteria | cpe:2.3:a:ruby-lang:date:*:*:*:*:*:ruby:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:a:ruby-lang:date:3.2.0:*:*:*:*:ruby:*:* | ||
>= 2.6.0, < 2.6.9CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1 3.1.2 3.0.2 and 2.0.1.
Jan 11, 2022Regular expression denial of service vulnerability (ReDoS) in date
Nov 16, 2021ruby: Regular expression denial of service vulnerability of Date parsing methods
Nov 15, 2021