CVE-2023-28756
A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.
- Ruby-lang Ruby
- ≤ 2.7.7
- Ruby-lang Time
- = 0.1.0, 0.2.1
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 2.5% (83th percentile)
- Weakness
- CWE-1333
- NVD status
- Modified
- Published
- 2023-03-31
CVE-2023-28756 at NVD
No indexed exploits for CVE-2023-28756 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-28756 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.