Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hgg7-cghq-xhf4

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

Ruby vulnerable to denial of service

When reading text nodes from an XML document, the REXML parser can be coerced in to allocating extremely large string objects which can consume all of the memory on a machine, causing a denial of service.

Jruby resolves this bug in version 1.7.3 as noted in https://www.jruby.org/2013/02/21/jruby-1-7-3.html

Пакеты

Наименование

org.jruby:jruby

maven
Затронутые версииВерсия исправления

< 1.7.3

1.7.3

EPSS

Процентиль: 95%
0.19831
Средний

Дефекты

CWE-400

Связанные уязвимости

ubuntu
больше 12 лет назад

lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows remote attackers to cause a denial of service (memory consumption and crash) via crafted text nodes in an XML document, aka an XML Entity Expansion (XEE) attack.

redhat
больше 12 лет назад

lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows remote attackers to cause a denial of service (memory consumption and crash) via crafted text nodes in an XML document, aka an XML Entity Expansion (XEE) attack.

nvd
больше 12 лет назад

lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows remote attackers to cause a denial of service (memory consumption and crash) via crafted text nodes in an XML document, aka an XML Entity Expansion (XEE) attack.

debian
больше 12 лет назад

lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows ...

oracle-oval
больше 12 лет назад

ELSA-2013-0611: ruby security update (MODERATE)

EPSS

Процентиль: 95%
0.19831
Средний

Дефекты

CWE-400