PT-2021-4288 · Ruby+2 · Bindata+2

·

CVE-2021-32823

·

Published

2021-05-18

·

Updated

2024-08-21

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions bindata RubyGem versions prior to 2.4.10
Description The issue is related to a potential denial-of-service vulnerability in the bindata RubyGem. In affected versions, it is very slow for certain classes in BinData to be created, such as BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, and BinData::Bit<N>. When combined with <user input>.constantize, there is a potential for a CPU-based denial-of-service attack. This vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations For bindata RubyGem versions prior to 2.4.10, update to version 2.4.10 or later, which improves the creation time of Bits and Integers, addressing the potential denial-of-service vulnerability. As a temporary workaround, consider restricting the use of the vulnerable classes, such as BinData::Bit<N>, to minimize the risk of exploitation. Additionally, avoid using the <user input>.constantize method in combination with these classes until the issue is resolved.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04897
BIT-GITLAB-2021-32823
CVE-2021-32823
GHSA-HJ56-84JW-67H6

Affected Products

Debian
Gitlab
Bindata