Vulnerabilities (CVE)

Filtered by vendor Ruby-lang Subscribe
Filtered by product Time
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-28756 3 Debian, Fedoraproject, Ruby-lang 4 Debian Linux, Fedora, Ruby and 1 more 2024-02-28 N/A 5.3 MEDIUM
A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.