CVE-2021-4250

LOW

active_attr < 0.15.3 - Denial of Service in Boolean Typecaster Regex Handler

Title source: llm
STIX 2.1

Description

A vulnerability classified as problematic has been found in cgriego active_attr up to 0.15.2. This affects the function call of the file lib/active_attr/typecasting/boolean_typecaster.rb of the component Regex Handler. The manipulation of the argument value leads to denial of service. The exploit has been disclosed to the public and may be used. Upgrading to version 0.15.3 is able to address this issue. The name of the patch is dab95e5843b01525444b82bd7b336ef1d79377df. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216207.

References (5)

Core 5
Core References
Third Party Advisory technical-description vdb-entry
https://vuldb.com/?id.216207
Exploit, Issue Tracking, Patch, Third Party Advisory exploit issue-tracking
https://github.com/cgriego/active_attr/issues/184
Patch, Third Party Advisory related
https://github.com/cgriego/active_attr/pull/185
Release Notes, Third Party Advisory mitigation
https://github.com/cgriego/active_attr/releases/tag/v0.15.3

Scores

CVSS v3 3.5
EPSS 0.0088
EPSS Percentile 75.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-404
Status published
Products (2)
active_attr_project/active_attr < 0.15.3
rubygems/active_attr 0 - 0.15.4RubyGems
Published Dec 18, 2022
Tracked Since Feb 18, 2026