WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by looping/backtracking. A victim must expose a WEBrick server that uses DigestAuth to the Internet or a untrusted network.
| Software | From | Fixed in |
|---|---|---|
| ruby-lang / ruby | 2.6.0 | 2.6.4.x |
| ruby-lang / ruby | 2.5.0 | 2.5.6.x |
| ruby-lang / ruby | 2.4.0 | 2.4.7.x |
| debian / debian_linux | 8.0 | 8.0.x |