Incorrect Regular Expression in Ruby on Rails - CVE-2021-22880
Published: February 11, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect regular expression for money processing format in the PostgreSQL adapter. A remote attacker can pass specially crafted input to the application and perform a regular expression denial of service (ReDOS) attack.
Affected software
rails (Debian package)
ruby2.5-rubygem-activerecord-5_1
rubygem-activerecord
rubygem-actionpack
OpenStack Cloud Crowbar
SUSE Linux Enterprise High Availability
Fedora
How to mitigate CVE-2021-22880
rails (Debian package) - update to 2:5.2.2.1+dfsg-1+deb10u3
ruby2.5-rubygem-activerecord-5_1 - update to 5.1.4-5.3.3
rubygem-activerecord - addressed in versions 5.2.3-5.fc32, 6.0.3.4-2.fc33
rubygem-actionpack - update to 6.0.3.4-2.fc33