Input validation error in Ruby on Rails - CVE-2023-22796

 

Input validation error in Ruby on Rails - CVE-2023-22796

Published: January 18, 2023


Vulnerability identifier: #VU71303
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-22796
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a regular expression based denial of service (ReDoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in Active Support in Inflector.underscore. A remote attacker can pass specially crafted input to the application and perform a regular expression based denial of service (ReDoS) attack.


Affected software

Ruby on Rails
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise High Availability
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
openEuler
Fedora
OpenShift Logging
Red Hat Satellite
ruby2.1-rubygem-activesupport-4_2
ruby2.5-rubygem-activesupport-5_1
ruby2.5-rubygem-activesupport-doc-5_1
rubygem-activesupport
rubygem-activesupport-doc
rubygem-actioncable-7.0.4.2-1.fc38 rubygem-actionmailbox-7.0.4.2-1.fc38 rubygem-actionmailer-7.0.4.2-1.fc38 rubygem-actionpack-7.0.4.2-1.fc38 rubygem-actiontext-7.0.4.2-1.fc38 rubygem-actionview-7.0.4.2-1.fc38 rubygem-activejob-7.0.4.2-1.fc38 rubygem-acti

How to mitigate CVE-2023-22796

Install updates from vendor's website.

Ruby on Rails - addressed in versions 6.1.7.1, 7.0.4.1
OpenShift Logging - update to 5.7.4
ruby2.1-rubygem-activesupport-4_2 - update to 4.2.9-7.15.1
ruby2.5-rubygem-activesupport-5_1 - update to 5.1.4-150000.3.12.1
ruby2.5-rubygem-activesupport-doc-5_1 - update to 5.1.4-150000.3.12.1
rubygem-activesupport - addressed in versions 5.2.4.4-1, 6.1.4.1-2, 6.1.4.1-3
rubygem-activesupport-doc - addressed in versions 5.2.4.4-1, 6.1.4.1-2, 6.1.4.1-3
Red Hat Satellite - update to 6.14
rubygem-actioncable-7.0.4.2-1.fc38 rubygem-actionmailbox-7.0.4.2-1.fc38 rubygem-actionmailer-7.0.4.2-1.fc38 rubygem-actionpack-7.0.4.2-1.fc38 rubygem-actiontext-7.0.4.2-1.fc38 rubygem-actionview-7.0.4.2-1.fc38 rubygem-activejob-7.0.4.2-1.fc38 rubygem-acti - update to 7.0.4.2-1.fc38

External References

Related Security Bulletins