icon

We found results for “

CVE-2021-32763

Date: July 20, 2021

OpenProject is open-source, web-based project management software. In versions prior to 11.3.3, the "MessagesController" class of OpenProject has a "quote" method that implements the logic behind the Quote button in the discussion forums, and it uses a regex to strip "<pre>" tags from the message being quoted. The "(.|\s)" part can match a space character in two ways, so an unterminated "<pre>" tag containing "n" spaces causes Ruby's regex engine to backtrack to try 2<sup>n</sup> states in the NFA. This will result in a Regular Expression Denial of Service. The issue is fixed in OpenProject 11.3.3. As a workaround, one may install the patch manually.

Language: Ruby

Severity Score

Severity Score

Weakness Type (CWE)

Uncontrolled Resource Consumption

CWE-400

Insufficient Information

NVD-CWE-noinfo

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): LOW

CVSS v2

Base Score:
Access Vector (AV): NETWORK
Access Complexity (AC): LOW
Authentication (AU): SINGLE
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): PARTIAL
Additional information:

Do you need more information?

Contact Us