PT-2023-3595 · Ruby+11 · Ruby Uri+11

Dominic Couture

·

Published

2023-03-21

·

Updated

2025-12-12

·

CVE-2023-28755

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Ruby URI component versions prior to 0.12.1 Ruby URI component versions prior to 0.11.1 Ruby URI component versions prior to 0.10.2 Ruby URI component version 0.10.0
Description The issue is related to the incorrect implementation of handling invalid URLs in the Ruby URI component. This allows a remote attacker to cause a denial of service by exploiting the ReDoS vulnerability, which causes an increase in execution time for parsing strings to URI objects when encountering specific characters in invalid URLs.
Recommendations For Ruby URI component versions prior to 0.12.1, update to version 0.12.1 or later. For Ruby URI component versions prior to 0.11.1, update to version 0.11.1 or later. For Ruby URI component versions prior to 0.10.2, update to version 0.10.2 or later. For Ruby URI component version 0.10.0, update to version 0.10.0.1 or later.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

ALSA-2023:3821
ALSA-2023:7025
ALSA-2024:1431
ALSA-2024:1576
ALSA-2024:3500
ALSA-2024:3838
ALSA-2024:4499
ALSA-2024_1431
ALSA-2024_1576
ALSA-2025_16880
ALT-PU-2023-7986
ALT-PU-2024-2130
BDU:2023-03870
CESA-2023_3821
CESA-2023_7025
CESA-2024_1431
CESA-2024_3500
CVE-2023-28755
DLA-3408-1
DLA-3447-1
DLA-3858-1
DLA-4163-1
ECHO-97F1-838F-206B
GHSA-HV5J-3H9F-99C2
INFSA-2024_3500
INFSA-2024_3838
OESA-2023-1226
OPENSUSE-SU-2023_4176-1
OPENSUSE-SU-2024:12828-1
OPENSUSE-SU-2024:12849-1
OPENSUSE-SU-2024:13623-1
OPENSUSE-SU-2025:14621-1
OPENSUSE-SU-2025:15819-1
RHSA-2023:3291
RHSA-2023:3821
RHSA-2023:7025
RHSA-2023_3821
RHSA-2023_7025
RHSA-2024:1431
RHSA-2024:1576
RHSA-2024:3500
RHSA-2024:3838
RHSA-2024_1431
RHSA-2024_1576
RHSA-2024_3500
RHSA-2024_3838
RLSA-2023:3821
RLSA-2024:1431
RLSA-2024:1576
SUSE-SU-2023:4176-1
USN-6055-1
USN-6055-2
USN-6087-1
USN-6181-1
USN-6219-1
USN-7735-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Ruby Uri
Suse
Ubuntu