CVE Vulnerabilities

CVE-2024-27282

Published: May 14, 2024 | Modified: May 14, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.6 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
Ubuntu
MEDIUM

An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 8 RedHat ruby:3.0-8100020240522072634.489197e6 *
Red Hat Enterprise Linux 8 RedHat ruby:3.1-8100020240510101534.489197e6 *
Red Hat Enterprise Linux 8 RedHat ruby:3.3-8100020240522151542.489197e6 *
Red Hat Enterprise Linux 8 RedHat ruby:2.5-8100020240627152904.489197e6 *
Red Hat Enterprise Linux 9 RedHat ruby:3.1-9040020240503183840.9 *
Red Hat Enterprise Linux 9 RedHat ruby:3.3-9040020240522171337.9 *
Red Hat Enterprise Linux 9 RedHat ruby-0:3.0.7-162.el9_4 *
Jruby Ubuntu mantic *
Ruby2.5 Ubuntu esm-infra/bionic *
Ruby2.7 Ubuntu focal *
Ruby3.0 Ubuntu jammy *
Ruby3.0 Ubuntu upstream *
Ruby3.1 Ubuntu mantic *
Ruby3.1 Ubuntu upstream *
Ruby3.2 Ubuntu devel *
Ruby3.2 Ubuntu noble *
Ruby3.2 Ubuntu upstream *

References