websocket-extensions Project websocket-extensions 0.1.0 for Ruby

CPE Details

websocket-extensions Project websocket-extensions 0.1.0 for Ruby
0.1.0
2020-10-19 10:05 +00:00
2020-10-19 10:05 +00:00

Alerte pour un CPE

Stay informed of any changes for a specific CPE.
Alert management

CPE Name: cpe:2.3:a:websocket-extensions_project:websocket-extensions:0.1.0:*:*:*:*:ruby:*:*

Informations

Vendor

websocket-extensions_project

Product

websocket-extensions

Version

0.1.0

Target Software

ruby

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-7663 2020-06-02 16:25 +00:00 websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.
7.5
HIGH
Click on the button to the left (OFF), to authorize the inscription of cookie improving the functionalities of the site. Click on the button to the left (Accept all), to unauthorize the inscription of cookie improving the functionalities of the site.