#VU77803 Incorrect Regular Expression in URI - CVE-2023-36617
Published: June 29, 2023
URI
rubygems.org
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation when parsing URL. A remote attacker can pass specially crafted URL to the application and perform regular expression denial of service (ReDos) attack.
Note, the vulnerability exists due to incomplete fix for #VU74004 (CVE-2023-28755).