PoC Index

CVE-2024-27282

MEDIUM 6.6EPSS 0.6%

An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.

CVSS v3.1
6.6 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
EPSS
0.63% chance of exploitation in the next 30 days, 48th percentile
Published
2024-05-08
Updated
2025-11-04

Proof-of-concept exploits (2)

References

Related