Incorrect Regular Expression in globalid - CVE-2023-22799
Published: February 9, 2023
Vulnerability identifier: #VU72084
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-22799
CWE-ID: CWE-185
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect parsing of model name. A remote attacker can pass specially crafted input to the application and consume excessive CPU resources, resulting in regular expression denial of service.
Affected software
globalid
SUSE Linux Enterprise High Availability
openSUSE Leap
openEuler
ruby2.5-rubygem-globalid
ruby2.5-rubygem-globalid-doc
rubygem-globalid
rubygem-globalid-doc
Red Hat Satellite
SUSE Linux Enterprise High Availability
openSUSE Leap
openEuler
ruby2.5-rubygem-globalid
ruby2.5-rubygem-globalid-doc
rubygem-globalid
rubygem-globalid-doc
Red Hat Satellite
How to mitigate CVE-2023-22799
Install updates from vendor's website.
globalid - update to 1.0.1
ruby2.5-rubygem-globalid - update to 0.4.1-150000.3.3.1
ruby2.5-rubygem-globalid-doc - update to 0.4.1-150000.3.3.1
rubygem-globalid - addressed in versions 0.4.2-3, 0.4.2-4
rubygem-globalid-doc - addressed in versions 0.4.2-3, 0.4.2-4
Red Hat Satellite - update to 6.14
ruby2.5-rubygem-globalid - update to 0.4.1-150000.3.3.1
ruby2.5-rubygem-globalid-doc - update to 0.4.1-150000.3.3.1
rubygem-globalid - addressed in versions 0.4.2-3, 0.4.2-4
rubygem-globalid-doc - addressed in versions 0.4.2-3, 0.4.2-4
Red Hat Satellite - update to 6.14
External References
Related Security Bulletins
- Incorrect regular expression in rubygems globalid
- SUSE update for rubygem-globalid
- Multiple vulnerabilities in Red Hat Satellite 6.14
- openEuler 20.03 LTS SP1 update for rubygem-globalid
- openEuler 20.03 LTS SP3 update for rubygem-globalid
- openEuler 22.03 LTS update for rubygem-globalid
- openEuler 22.03 LTS SP1 update for rubygem-globalid