CVE-2021-41816

CRITICAL9.8EPSS 0.48%

Buffer overrun in CGI.escape_html

發布日:2021/12/14修改日:2026/4/28
也稱為:GHSA-5cqm-crxm-6qpvALPINE-CVE-2021-41816CGA-69x2-22v3-4fgqDEBIAN-CVE-2021-41816

描述

CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This also affects the CGI gem before 0.3.1 for Ruby.

受影響套件(4)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

參考連結(18)