CVE-2011-4838JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
CWE-400 · Uncontrolled resource consumption
No public exploit
Nothing published shows this CVE being exploited, which is not the same as ruling it out. nothing published in 14 years.
CVSS E:U
Not a Java vulnerability. Outside ARMR's domain entirely.
| Decided by | unmatched-product : No tracked product matched above, and none present at all |
|---|---|
| Finding | Affected product (jruby/jruby) is not in our known products list |
AV:N/AC:L/Au:N/C:N/I:N/A:P
1 metric
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 2.0 | 5.0 | no band published | AV:N/AC:L/Au:N/C:N/I:N/A:P |
NVD | Primary | published |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | jruby | jruby | generic | < 1.6.5.1 |
| URL | Tags |
|---|---|
| http://archives.neohapsis.com/archives/bugtraq/2011-12/0181.html | Broken Link |
| http://jruby.org/2011/12/27/jruby-1-6-5-1.html | Vendor Advisory |
| http://rhn.redhat.com/errata/RHSA-2012-1232.html | Broken Link |
| http://secunia.com/advisories/47407 | Third Party Advisory |
| http://secunia.com/advisories/50084 | Third Party Advisory |
| http://security.gentoo.org/glsa/glsa-201207-06.xml | Third Party Advisory |
| http://www.kb.cert.org/vuls/id/903934 | Third Party Advisory, US Government Resource |
| http://www.nruns.com/_downloads/advisory28122011.pdf | Third Party Advisory |
| http://www.ocert.org/advisories/ocert-2011-003.html | Third Party Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/72019 | Third Party Advisory, VDB Entry |
| Published | 2011-12-30 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-16 | NVD's own last-modified date for this record. |