MEDIUM 6.6 Microsoft

CVE-2024-27282

An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler it is possible to extract arbitrary heap data relative to the start of the text including pointers and sensitive strings. The fixed versions are 3.0.7 3.1.5 3.2.4 and 3.3.1.

Microsoft Security Update 2024-May: An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler it is possible to extract arbitrary heap data relative to the start of the text including pointers and sensitive strings. The fixed versions are 3.0.7 3.1.5 3.2.4 and 3.3.1.

Affected Products

References

Published: 2024-05-14 · Source: Microsoft · Feed updated: 2026-08-04
This medium severity vulnerability with a CVSS score of 6.6 was published on 2024-05-14 via Microsoft. Affected: cbl2 ruby 3.1.4-5 on CBL Mariner 2.0, azl3 ruby 3.3.3-1 on Azure Linux 3.0, azl3 ruby 3.3.0-4 on Azure Linux 3.0 and 1 more.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.