Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-16201

WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by looping/backtracking. A victim must expose a WEBrick server that uses DigestAuth to the Internet or a untrusted network.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.0%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 7.8
References
Products affected by CVE-2019-16201
  • Ruby-Lang » Ruby » Version: 2.4.0
    cpe:2.3:a:ruby-lang:ruby:2.4.0
  • Ruby-Lang » Ruby » Version: 2.4.1
    cpe:2.3:a:ruby-lang:ruby:2.4.1
  • Ruby-Lang » Ruby » Version: 2.4.2
    cpe:2.3:a:ruby-lang:ruby:2.4.2
  • Ruby-Lang » Ruby » Version: 2.4.3
    cpe:2.3:a:ruby-lang:ruby:2.4.3
  • Ruby-Lang » Ruby » Version: 2.4.4
    cpe:2.3:a:ruby-lang:ruby:2.4.4
  • Ruby-Lang » Ruby » Version: 2.4.5
    cpe:2.3:a:ruby-lang:ruby:2.4.5
  • Ruby-Lang » Ruby » Version: 2.4.6
    cpe:2.3:a:ruby-lang:ruby:2.4.6
  • Ruby-Lang » Ruby » Version: 2.4.7
    cpe:2.3:a:ruby-lang:ruby:2.4.7
  • Ruby-Lang » Ruby » Version: 2.5.0
    cpe:2.3:a:ruby-lang:ruby:2.5.0
  • Ruby-Lang » Ruby » Version: 2.5.1
    cpe:2.3:a:ruby-lang:ruby:2.5.1
  • Ruby-Lang » Ruby » Version: 2.5.2
    cpe:2.3:a:ruby-lang:ruby:2.5.2
  • Ruby-Lang » Ruby » Version: 2.5.3
    cpe:2.3:a:ruby-lang:ruby:2.5.3
  • Ruby-Lang » Ruby » Version: 2.5.4
    cpe:2.3:a:ruby-lang:ruby:2.5.4
  • Ruby-Lang » Ruby » Version: 2.5.5
    cpe:2.3:a:ruby-lang:ruby:2.5.5
  • Ruby-Lang » Ruby » Version: 2.5.6
    cpe:2.3:a:ruby-lang:ruby:2.5.6
  • Ruby-Lang » Ruby » Version: 2.6.0
    cpe:2.3:a:ruby-lang:ruby:2.6.0
  • Ruby-Lang » Ruby » Version: 2.6.1
    cpe:2.3:a:ruby-lang:ruby:2.6.1
  • Ruby-Lang » Ruby » Version: 2.6.2
    cpe:2.3:a:ruby-lang:ruby:2.6.2
  • Ruby-Lang » Ruby » Version: 2.6.3
    cpe:2.3:a:ruby-lang:ruby:2.6.3
  • Ruby-Lang » Ruby » Version: 2.6.4
    cpe:2.3:a:ruby-lang:ruby:2.6.4
  • Debian » Debian Linux » Version: 8.0
    cpe:2.3:o:debian:debian_linux:8.0


Contact Us

Shodan ® - All rights reserved