Potential Denial-of-Service in bindata
Vulnerability Description
In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit<N>. In combination with <user_input>.constantize there is a potential for a CPU-based DoS. In version 2.4.10 bindata improved the creation time of Bits and Integers.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-32823
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/dmendel/bindata/commit/d99f050b88337559be2cb35906c1f8da49531323
- https://github.com/rubysec/ruby-advisory-db/issues/476
- https://about.gitlab.com/releases/2021/06/01/security-release-gitlab-13-12-2-released/#update-bindata-dependency
- https://rubygems.org/gems/bindata
- https://github.com/dmendel/bindata/blob/v2.4.10/ChangeLog.rdoc#version-2410-2021-05-18-
Affected Vendor
dmendel
View all reports →