- Description
- In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.
- Source
- cve@mitre.org
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
- Hype score
- Not currently trending
🚨 Lambda Watchdog detected a new MEDIUM severity CVE 🚨 CVE-2025-27220 was detected in the latest AWS Lambda image scan affecting the cgi package in 2 images. Check the full report 👉 https://t.co/6EUGaPyRZk #AWS #Lambda #CVE #CloudSecurity #Serverless
@LambdaWatchdog
4 Mar 2025
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 CGI, Regular Expression Denial of Service (ReDoS), #CVE-2025-27220 (High) https://t.co/UaGj0si8yn
@dailycve
3 Mar 2025
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Ruby News ➜ Security advisories: CVE-2025-27219, CVE-2025-27220 and CVE-2025-27221 https://t.co/lhGgOXB5Hx
@rubylandnews
26 Feb 2025
81 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ruby-lang:cgi:*:*:*:*:*:ruby:*:*",
"vulnerable": true,
"matchCriteriaId": "E7161F63-FEE1-4803-A460-FE87E323B05D",
"versionEndExcluding": "0.3.5.1"
},
{
"criteria": "cpe:2.3:a:ruby-lang:cgi:*:*:*:*:*:ruby:*:*",
"vulnerable": true,
"matchCriteriaId": "A30117BA-C46E-44BB-A581-86E43F37D6E4",
"versionEndExcluding": "0.4.2",
"versionStartIncluding": "0.4.0"
},
{
"criteria": "cpe:2.3:a:ruby-lang:cgi:0.3.6:*:*:*:*:ruby:*:*",
"vulnerable": true,
"matchCriteriaId": "8AE1C5F9-0743-49A2-8292-0018FEEF81E0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:3.1.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DD748C02-1E5E-4D92-9C41-2BF953874C32"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:3.2.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8850AECE-0966-403B-A0D8-694C3ECE39D4"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]