In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| cgi(RubyGems) | 0 | 0.3.5.1 | N/A |
| cgi(RubyGems) | 0.3.6 | 0.3.7 | N/A |
| cgi(RubyGems) | 0.4.0 | 0.4.2 | N/A |
CVSS Metrics