CVE-2014-6438
The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service
The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service (catastrophic regular expression backtracking, resource consumption, or application crash) via a crafted string.
HIGH · CVSS 7.5
EPSS 0.01127
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules3
YARA rules0