CVE-2024-27282
MEDIUM6.6EPSS 0.70%發布日:2024/5/14修改日:2025/12/3
也稱為:ALPINE-CVE-2024-27282
描述
An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.
受影響套件(5)
- Alpine/rubyfrom 0, < 3.1.5-r0
- Bitnami/rubyfrom 0, < 3.1.5, >= 3.2.0, < 3.2.4, >= 3.3.0, < 3.3.1
- Bitnami/ruby-minfrom 0, < 3.1.6, >= 3.2.0, < 3.2.6, >= 3.3.0, < 3.3.7
- Debian/ruby2.7from 0, < 2.7.4-1+deb11u2
- Debian/ruby3.1from 0, < 3.1.2-7+deb12u1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L |
參考連結(9)
- ADVISORYhttps://security.alpinelinux.org/vuln/CVE-2024-27282
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2024-27282
- WEBhttps://hackerone.com/reports/2122624
- WEBhttps://lists.debian.org/debian-lts-announce/2024/09/msg00000.html
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/XYDHPHEZI7OQXTQKTDZHGZNPIJH7ZV5N/
- WEBhttps://nvd.nist.gov/vuln/detail/CVE-2024-27282
- WEBhttps://security.netapp.com/advisory/ntap-20241011-0007/
- WEBhttps://www.ruby-lang.org/en/news/2024/04/23/arbitrary-memory-address-read-regexp-cve-2024-27282/