Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-43398

Опубликовано: 22 авг. 2024
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like REXML::Document.new, you may be impacted to this vulnerability. If you use other parser APIs such as stream parser API and SAX2 parser API, this vulnerability is not affected. The REXML gem 3.3.6 or later include the patch to fix the vulnerability.

A vulnerability was found in REXML RubyGems. This package is vulnerable to denial of service (DoS) when parsing a deep XML structure with the same local name attribute. This vulnerability only affects tree parser API like REXML::Document.new, other parser APIs such as stream parser API and SAX2 parser API are not affected.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp-backend-containerAffected
Red Hat 3scale API Management Platform 23scale-amp-system-containerAffected
Red Hat 3scale API Management Platform 23scale-amp-zync-containerAffected
Red Hat 3scale API Management Platform 23scale-toolbox-containerAffected
Red Hat Enterprise Linux 10rubyNot affected
Red Hat Enterprise Linux 10ruby:3.3/rubyNot affected
Red Hat Enterprise Linux 8rubyWill not fix
Red Hat Enterprise Linux 8ruby:2.5/rubyWill not fix
Red Hat Enterprise Linux 9pcsWill not fix
Red Hat Enterprise Linux 9rubyWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-776

EPSS

Процентиль: 44%
0.00208
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
10 месяцев назад

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like REXML::Document.new, you may be impacted to this vulnerability. If you use other parser APIs such as stream parser API and SAX2 parser API, this vulnerability is not affected. The REXML gem 3.3.6 or later include the patch to fix the vulnerability.

CVSS3: 5.9
nvd
10 месяцев назад

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like REXML::Document.new, you may be impacted to this vulnerability. If you use other parser APIs such as stream parser API and SAX2 parser API, this vulnerability is not affected. The REXML gem 3.3.6 or later include the patch to fix the vulnerability.

CVSS3: 5.9
msrc
6 месяцев назад

Описание отсутствует

CVSS3: 5.9
debian
10 месяцев назад

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS ...

CVSS3: 5.9
github
10 месяцев назад

REXML denial of service vulnerability

EPSS

Процентиль: 44%
0.00208
Низкий

5.9 Medium

CVSS3