Denial of Service Vulnerability in GlobalID by Ruby on Rails
CVE-2023-22799
7.5HIGH
What is CVE-2023-22799?
A vulnerability exists in GlobalID versions prior to 1.0.1, where a specially crafted input can exploit the regular expression engine. This can lead to a Denial of Service (DoS) condition, as the engine may take an excessively long time to process the input, affecting application performance. Users are strongly advised to upgrade to a secure version or implement available workarounds to mitigate this issue.
Affected Version(s)
https://github.com/rails/globalid 1.0.1