Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2rxp-v6pw-ch6m

Опубликовано: 28 окт. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.6
CVSS3: 7.5

Описание

REXML ReDoS vulnerability

Impact

The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;).

This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03.

Patches

The REXML gem 3.3.9 or later include the patch to fix the vulnerability.

Workarounds

Use Ruby 3.2 or later instead of Ruby 3.1.

References

Пакеты

Наименование

rexml

rubygems
Затронутые версииВерсия исправления

< 3.3.9

3.3.9

EPSS

Процентиль: 57%
0.00361
Низкий

6.6 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 7.5
ubuntu
8 месяцев назад

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.

CVSS3: 7.5
redhat
8 месяцев назад

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.

CVSS3: 7.5
nvd
8 месяцев назад

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.

CVSS3: 7.5
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
8 месяцев назад

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReD ...

EPSS

Процентиль: 57%
0.00361
Низкий

6.6 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-1333