For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to perform system management tasks.
The following packages have been upgraded to a later upstream version: ruby
(2.7). (BZ#2189465)
Security Fix(es):
* ruby/cgi-gem: HTTP response splitting in CGI (CVE-2021-33621)
* ruby: ReDoS vulnerability in URI (CVE-2023-28755)
* ruby: ReDoS vulnerability in Time (CVE-2023-28756)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
https://access.redhat.com/security/cve/CVE-2021-33621 https://access.redhat.com/security/cve/CVE-2023-28755 https://access.redhat.com/security/cve/CVE-2023-28756 https://access.redhat.com/security/updates/classification/#moderate
Red Hat Enterprise Linux AppStream (v. 8):
Source:
ruby-2.7.8-139.module+el8.8.0+18745+f1bef313.src.rpm
rubygem-abrt-0.4.0-1.module+el8.3.0+7192+4e3a532a.src.rpm
rubygem-bson-4.8.1-1.module+el8.3.0+7192+4e3a532a.src.rpm
rubygem-mongo-2.11.3-1.module+el8.3.0+7192+4e3a532a.src.rpm
rubygem-mysql2-0.5.3-1.module+el8.3.0+7192+4e3a532a.src.rpm
rubygem-pg-1.2.3-1.module+el8.3.0+7192+4e3a532a.src.rpm
aarch64:
ruby-2.7.8-139.module+el8.8.0+18745+f1bef313.aarch64.rpm
ruby-debuginfo-2.7.8-139.module+el8.8.0+18745+f1bef313.aarch64.rpm
ruby-debugsource-2.7.8-139.module+el8.8.0+18745+f1bef313.aarch64.rpm
ruby-devel-2.7.8-139.module+el8.8.0+18745+f1bef313.aarch64.rpm
ruby-libs-2.7.8-139.module+el8.8.0+18745+f1bef313.aarch64.rpm
ruby-libs-debuginfo-2.7.8-139.module+el8.8.0+18745+f1bef313.aarch64.rpm
rubygem-bigdecimal-2.0.0-139.module+el8.8.0+18745+f1bef313.aarch64.rpm
rubygem-bigdecimal-debuginfo-2.0.0-139.module+el8.8.0+18745+f1bef313.aarch64.rpm
rubygem-bson-4.8.1-1.module+el8.3.0+7192+4e3a532a.aarch64.rpm
rubygem-bson-debuginfo-4.8.1-1.module+el8.3.0+7192+4e3a532a.aarch64.rpm
rubygem-bson-debugsource-4.8.1-1.module+el8.3.0+7192+4e3a532a.aarch64.rpm
rubygem-io-console-0.5.6-139.module+el8.8.0+18745+f1bef313.aarch64.rpm
Read the Full Advisory
An update for the ruby:2.7 module is now available for Red Hat EnterpriseLinux 8.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64
2149706 - CVE-2021-33621 ruby/cgi-gem: HTTP response splitting in CGI
2184059 - CVE-2023-28755 ruby: ReDoS vulnerability in URI
2184061 - CVE-2023-28756 ruby: ReDoS vulnerability in Time
2189465 - ruby:2.7/ruby: Rebase to the latest Ruby 2.7 release [rhel-8] [rhel-8.8.0.z]
Get the latest Linux and open source security news straight to your inbox.