Incorrect Regular Expression in globalid - CVE-2023-22799

 

Incorrect Regular Expression in globalid - CVE-2023-22799

Published: February 9, 2023


Vulnerability identifier: #VU72084
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-22799
CWE-ID: CWE-185
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect parsing of model name. A remote attacker can pass specially crafted input to the application and consume excessive CPU resources, resulting in regular expression denial of service.


Affected software

globalid
SUSE Linux Enterprise High Availability
openSUSE Leap
openEuler
ruby2.5-rubygem-globalid
ruby2.5-rubygem-globalid-doc
rubygem-globalid
rubygem-globalid-doc
Red Hat Satellite

How to mitigate CVE-2023-22799

Install updates from vendor's website.

globalid - update to 1.0.1
ruby2.5-rubygem-globalid - update to 0.4.1-150000.3.3.1
ruby2.5-rubygem-globalid-doc - update to 0.4.1-150000.3.3.1
rubygem-globalid - addressed in versions 0.4.2-3, 0.4.2-4
rubygem-globalid-doc - addressed in versions 0.4.2-3, 0.4.2-4
Red Hat Satellite - update to 6.14

External References

Related Security Bulletins