Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-35176

Опубликовано: 16 мая 2024
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many <s in an attribute value. Those who need to parse untrusted XMLs may be impacted to this vulnerability. The REXML gem 3.2.7 or later include the patch to fix this vulnerability. As a workaround, don't parse untrusted XMLs.

EPSS

Процентиль: 92%
0.08427
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 года назад

REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `<`s in an attribute value. Those who need to parse untrusted XMLs may be impacted to this vulnerability. The REXML gem 3.2.7 or later include the patch to fix this vulnerability. As a workaround, don't parse untrusted XMLs.

CVSS3: 5.3
redhat
около 1 года назад

REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `<`s in an attribute value. Those who need to parse untrusted XMLs may be impacted to this vulnerability. The REXML gem 3.2.7 or later include the patch to fix this vulnerability. As a workaround, don't parse untrusted XMLs.

CVSS3: 5.3
msrc
около 1 года назад

Описание отсутствует

CVSS3: 5.3
debian
около 1 года назад

REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a den ...

CVSS3: 5.3
github
около 1 года назад

REXML contains a denial of service vulnerability

EPSS

Процентиль: 92%
0.08427
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400