« Volver al listado

CVE-2024-0241

Estado: ModificadaAlta (7.5)—

encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by sending an HTTP request with an extremely long "id" parameter.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-0241",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-0241",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-01-05T20:45:06.578790Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "disclosure@vulncheck.com",
      "affectedData": [
        {
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.0.0.beta2",
              "versionType": "custom"
            }
          ],
          "packageURL": "pkg:gem/encoded_id-rails",
          "packageName": "encoded_id-rails",
          "collectionURL": "https://rubygems.org",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-01-04T21:15:09.267",
  "references": [
    {
      "url": "https://github.com/advisories/GHSA-3px7-jm2p-6h2c",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "disclosure@vulncheck.com"
    },
    {
      "url": "https://github.com/stevegeek/encoded_id-rails/commit/afa495a77b8a21ad582611f9cdc2081dc4018b91",
      "tags": [
        "Patch"
      ],
      "source": "disclosure@vulncheck.com"
    },
    {
      "url": "https://github.com/stevegeek/encoded_id-rails/security/advisories/GHSA-3px7-jm2p-6h2c",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "disclosure@vulncheck.com"
    },
    {
      "url": "https://vulncheck.com/advisories/vc-advisory-GHSA-3px7-jm2p-6h2c",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "disclosure@vulncheck.com"
    },
    {
      "url": "https://github.com/advisories/GHSA-3px7-jm2p-6h2c",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/stevegeek/encoded_id-rails/commit/afa495a77b8a21ad582611f9cdc2081dc4018b91",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/stevegeek/encoded_id-rails/security/advisories/GHSA-3px7-jm2p-6h2c",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://vulncheck.com/advisories/vc-advisory-GHSA-3px7-jm2p-6h2c",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "disclosure@vulncheck.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-770"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by sending an HTTP request with an extremely long \"id\" parameter."
    },
    {
      "lang": "es",
      "value": "Las versiones de encoded_id-rails anteriores a 1.0.0.beta2 se ven afectadas por una vulnerabilidad de consumo de recursos incontrolado. Un atacante remoto y no autenticado podría provocar una condición de denegación de servicio enviando una solicitud HTTP con un parámetro \"id\" extremadamente largo."
    }
  ],
  "lastModified": "2026-07-14T23:17:13.130",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:diaconou:encodedid\\:\\:rails:*:*:*:*:*:ruby:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E952EED-8C83-4839-9648-B77A49E76AAF",
              "versionEndExcluding": "1.0.0"
            },
            {
              "criteria": "cpe:2.3:a:diaconou:encodedid\\:\\:rails:1.0.0:-:*:*:*:ruby:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9886262-80F5-4465-B2A1-867060F8B378"
            },
            {
              "criteria": "cpe:2.3:a:diaconou:encodedid\\:\\:rails:1.0.0:beta1:*:*:*:ruby:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB04E949-0F60-4AB8-B16E-D06E7B02FDBA"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "disclosure@vulncheck.com"
}