GlobalID ReDoS Vulnerability <1.0.1
CVE-2023-22799 Published on February 9, 2023

A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately.

NVD

Weakness Type

What is a Resource Exhaustion Vulnerability?

The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

CVE-2023-22799 has been classified to as a Resource Exhaustion vulnerability or weakness.


Products Associated with CVE-2023-22799

Want to know whenever a new CVE is published for Ruby on Rails Globalid? stack.watch will email you.

 

Exploit Probability

EPSS
1.63%
Percentile
81.65%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.