In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.
| Software | From | Fixed in |
|---|---|---|
cgi
|
- | 0.3.5.1 |
cgi
|
0.3.6 | 0.3.6.x |
cgi
|
0.3.6 | 0.3.7 |
cgi
|
0.4.0 | 0.4.2 |
| ruby-lang / cgi | - | 0.3.5.1 |
| ruby-lang / cgi | 0.4.0 | 0.4.2 |
| ruby-lang / cgi | 0.3.6 | 0.3.6.x |