In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.
References
Configurations
No configuration.
History
04 Mar 2025, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-04 00:15
Updated : 2025-03-04 00:15
NVD link : CVE-2025-27220
Mitre link : CVE-2025-27220
CVE.ORG link : CVE-2025-27220
JSON object : View
Products Affected
No product.
CWE
CWE-1333
Inefficient Regular Expression Complexity