{"schema_version":"1.9.0","id":"GHSA-8hc4-xxm3-5ppp","published":"2021-03-02T03:44:14Z","modified":"2024-02-20T05:21:22.451179Z","aliases":["CVE-2021-22880"],"summary":"Active Record subject to Regular Expression Denial-of-Service (ReDoS)","details":"The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` type of the PostgreSQL adapter in Active Record to spend too much time in a regular expression, resulting in the potential for a DoS attack. This only impacts Rails applications that are using PostgreSQL along with money type columns that take user input.","affected":[{"package":{"name":"activerecord","ecosystem":"RubyGems","purl":"pkg:gem/activerecord"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.2.4.5"}]}],"versions":["5.0.0","5.0.0.1","5.0.1","5.0.1.rc1","5.0.1.rc2","5.0.2","5.0.2.rc1","5.0.3","5.0.4","5.0.4.rc1","5.0.5","5.0.5.rc1","5.0.5.rc2","5.0.6","5.0.6.rc1","5.0.7","5.0.7.1","5.0.7.2","5.1.0","5.1.0.beta1","5.1.0.rc1","5.1.0.rc2","5.1.1","5.1.2","5.1.2.rc1","5.1.3","5.1.3.rc1","5.1.3.rc2","5.1.3.rc3","5.1.4","5.1.4.rc1","5.1.5","5.1.5.rc1","5.1.6","5.1.6.1","5.1.6.2","5.1.7","5.1.7.rc1","5.2.0","5.2.0.beta1","5.2.0.beta2","5.2.0.rc1","5.2.0.rc2","5.2.1","5.2.1.1","5.2.1.rc1","5.2.2","5.2.2.1","5.2.2.rc1","5.2.3","5.2.3.rc1","5.2.4","5.2.4.1","5.2.4.2","5.2.4.3","5.2.4.4","5.2.4.rc1"],"database_specific":{"last_known_affected_version_range":"<= 5.2.4.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/03/GHSA-8hc4-xxm3-5ppp/GHSA-8hc4-xxm3-5ppp.json"}},{"package":{"name":"activerecord","ecosystem":"RubyGems","purl":"pkg:gem/activerecord"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0"},{"fixed":"6.0.3.5"}]}],"versions":["6.0.0","6.0.1","6.0.1.rc1","6.0.2","6.0.2.1","6.0.2.2","6.0.2.rc1","6.0.2.rc2","6.0.3","6.0.3.1","6.0.3.2","6.0.3.3","6.0.3.4","6.0.3.rc1"],"database_specific":{"last_known_affected_version_range":"<= 6.0.3.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/03/GHSA-8hc4-xxm3-5ppp/GHSA-8hc4-xxm3-5ppp.json"}},{"package":{"name":"activerecord","ecosystem":"RubyGems","purl":"pkg:gem/activerecord"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.1.0"},{"fixed":"6.1.2.1"}]}],"versions":["6.1.0","6.1.1","6.1.2"],"database_specific":{"last_known_affected_version_range":"<= 6.1.2.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/03/GHSA-8hc4-xxm3-5ppp/GHSA-8hc4-xxm3-5ppp.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-22880"},{"type":"WEB","url":"https://hackerone.com/reports/1023899"},{"type":"WEB","url":"https://discuss.rubyonrails.org/t/cve-2021-22880-possible-dos-vulnerability-in-active-record-postgresql-adapter/77129"},{"type":"WEB","url":"https://github.com/rails/rails"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activerecord/CVE-2021-22880.yml"},{"type":"WEB","url":"https://groups.google.com/g/rubyonrails-security/c/ZzUqCh9vyhI"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MO5OJ3F4ZL3UXVLJO6ECANRVZBNRS2IH"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XQ3NS4IBYE2I3MVMGAHFZBZBIZGHXHT3"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20210805-0009"},{"type":"WEB","url":"https://www.debian.org/security/2021/dsa-4929"}],"database_specific":{"cwe_ids":["CWE-400"],"github_reviewed":true,"github_reviewed_at":"2021-03-02T03:40:01Z","nvd_published_at":"2021-02-11T18:15:00Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}