VDB
KO
MEDIUM

GHSA-cg4j-q9v8-6v38

Rails Active Support has a possible ReDoS vulnerability in number_to_delimited

Details

### Impact `NumberToDelimitedConverter` used a regular expression with `gsub!` to insert thousands delimiters. This could produce quadratic time complexity on long digit strings.

### Releases The fixed releases are available at the normal locations.

### Credit This issue was responsibly reported by Hackerone researcher [scyoon](https://hackerone.com/scyoon).

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems / activesupport
Introduced in: 8.1.0.beta1 Fixed in: 8.1.2.1
Fix bundle update activesupport
RubyGems / activesupport
Introduced in: 8.0.0.beta1 Fixed in: 8.0.4.1
Fix bundle update activesupport
RubyGems / activesupport
Introduced in: 0 Fixed in: 7.2.3.1
Fix bundle update activesupport

References