CVE-2021-4250
LOWactive_attr < 0.15.3 - Denial of Service in Boolean Typecaster Regex Handler
Title source: llmDescription
A vulnerability classified as problematic has been found in cgriego active_attr up to 0.15.2. This affects the function call of the file lib/active_attr/typecasting/boolean_typecaster.rb of the component Regex Handler. The manipulation of the argument value leads to denial of service. The exploit has been disclosed to the public and may be used. Upgrading to version 0.15.3 is able to address this issue. The name of the patch is dab95e5843b01525444b82bd7b336ef1d79377df. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216207.
References (5)
Core 5
Core References
Third Party Advisory technical-description
vdb-entry
https://vuldb.com/?id.216207
Exploit, Issue Tracking, Patch, Third Party Advisory exploit
issue-tracking
https://github.com/cgriego/active_attr/issues/184
Patch, Third Party Advisory related
https://github.com/cgriego/active_attr/pull/185
Patch, Third Party Advisory mitigation
patch
https://github.com/cgriego/active_attr/commit/dab95e5843b01525444b82bd7b336ef1d79377df
Release Notes, Third Party Advisory mitigation
https://github.com/cgriego/active_attr/releases/tag/v0.15.3
Scores
CVSS v3
3.5
EPSS
0.0088
EPSS Percentile
75.6%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Details
CWE
CWE-404
Status
published
Products (2)
active_attr_project/active_attr
< 0.15.3
rubygems/active_attr
0 - 0.15.4RubyGems
Published
Dec 18, 2022
Tracked Since
Feb 18, 2026