VDB
CVE-2023-31606
CVE-2023-31606
PUBLISHED
CVSS 7.5 HIGH
A Regular Expression Denial of Service (ReDoS) issue was discovered in the sanitize_html function of redcloth gem v4.0.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
EPSS 0.91% · 76.3th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.91%
76.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| RubyGems | RedCloth | 0, 0, 0 |
| promptworks | redcloth | 4.0.0, 4.0.0, 4.0.0 |
| n/a | n/a | n/a, * |
Timeline
- Jun 6, 2023 CVE Published
- Jun 7, 2023 EPSS Score
- Jul 13, 2023 EPSS Score
- Sep 22, 2023 EPSS Score
- Oct 28, 2023 EPSS Score
- Dec 3, 2023 EPSS Score
- Feb 13, 2024 EPSS Score
- Mar 19, 2024 EPSS Score
- Apr 24, 2024 EPSS Score
- Jul 5, 2024 EPSS Score
- Aug 10, 2024 EPSS Score
- Sep 14, 2024 EPSS Score
References
- https://github.com/jgarber/redcloth/issues/73 url
- https://github.com/jgarber/redcloth url
- https://github.com/e23e/CVE-2023-31606#readme url
- [debian-lts-announce] 20230706 [SECURITY] [DLA 3480-1] ruby-redcloth security update mailing-list
- GLSA-202401-14 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-31606 advisory
- https://github.com/jgarber/redcloth/commit/8b1327688fef8e6617792054ef299d7bc74c0a1e url
- https://github.com/jgarber/redcloth/blob/v4.3.2/lib/redcloth/formatters/html.rb#L327 url
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/RedCloth/CVE-2023-31606.yml url