11---
22engine : ruby
33cve : 2018-8777
4+ ghsa : 9j6f-82h4-9mw2
45url : https://www.ruby-lang.org/en/news/2018/03/28/large-request-dos-in-webrick-cve-2018-8777/
56title : DoS by large request in WEBrick
67date : 2018-03-28
@@ -13,9 +14,34 @@ description: |
1314 DoS attack.
1415
1516 All users running an affected release should upgrade immediately.
17+ cvss_v2 : 5.0
18+ cvss_v3 : 7.5
1619patched_versions :
1720 - " ~> 2.2.10"
1821 - " ~> 2.3.7"
1922 - " ~> 2.4.4"
2023 - " ~> 2.5.1"
2124 - " > 2.6.0-preview1"
25+ related :
26+ url :
27+ - https://nvd.nist.gov/vuln/detail/CVE-2018-8777
28+ - https://www.ruby-lang.org/en/news/2018/03/28/large-request-dos-in-webrick-cve-2018-8777
29+ - https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-2-10-released
30+ - https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-3-7-released
31+ - https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-4-4-released
32+ - https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-5-1-released
33+ - https://www.ruby-lang.org/en/news/2018/05/31/ruby-2-6-0-preview2-released
34+ - https://usn.ubuntu.com/3685-1
35+ - https://lists.debian.org/debian-lts-announce/2018/04/msg00023.html
36+ - https://lists.debian.org/debian-lts-announce/2018/04/msg00024.html
37+ - https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html
38+ - https://www.debian.org/security/2018/dsa-4259
39+ - https://access.redhat.com/errata/RHSA-2018:3729
40+ - https://access.redhat.com/errata/RHSA-2018:3730
41+ - https://access.redhat.com/errata/RHSA-2018:3731
42+ - https://access.redhat.com/errata/RHSA-2019:2028
43+ - https://access.redhat.com/errata/RHSA-2020:0542
44+ - https://access.redhat.com/errata/RHSA-2020:0591
45+ - https://access.redhat.com/errata/RHSA-2020:0663
46+ - http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html
47+ - https://github.com/advisories/GHSA-9j6f-82h4-9mw2
0 commit comments