Description
The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service (catastrophic regular expression backtracking, resource consumption, or application crash) via a crafted string.
Remediation
References
Related Vulnerabilities
Chamilo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-40662)
markdown-it Inefficient Regular Expression Complexity Vulnerability (CVE-2015-10005)
PostgreSQL Numeric Errors Vulnerability (CVE-2010-0733)
WordPress Plugin WP Symposium Pro Social Network Multiple Vulnerabilities (15.12)
WordPress Plugin xili-tidy-tags Cross-Site Request Forgery (1.12.03)