CVE-2024-27282

MEDIUM

Ruby <3.3.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.

Scores

CVSS v3 6.6
EPSS 0.0057
EPSS Percentile 68.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125
Status published
Published May 14, 2024
Tracked Since Feb 18, 2026