websocket-extensions Project websocket-extensions 0.1.4 for Ruby

CPE Details

websocket-extensions Project websocket-extensions 0.1.4 for Ruby
0.1.4
2020-10-19
10h05 +00:00
2020-10-19
10h05 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:websocket-extensions_project:websocket-extensions:0.1.4:*:*:*:*:ruby:*:*

Informations

Vendor

websocket-extensions_project

Product

websocket-extensions

Version

0.1.4

Target Software

ruby

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-7663 2020-06-02 16h25 +00:00 websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.
7.5
High