Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-43398

Опубликовано: 22 авг. 2024
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 5.9

Описание

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like REXML::Document.new, you may be impacted to this vulnerability. If you use other parser APIs such as stream parser API and SAX2 parser API, this vulnerability is not affected. The REXML gem 3.3.6 or later include the patch to fix the vulnerability.

РелизСтатусПримечание
devel

DNE

esm-infra/focal

DNE

esm-infra/xenial

needs-triage

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

not-affected

2.7.0-5ubuntu1.16
focal

released

2.7.0-5ubuntu1.16
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

released

3.0.2-7ubuntu2.10
noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

released

3.2.3-1ubuntu0.24.04.5
oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

released

3.3.6-1.1ubuntu1
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

released

3.3.4-2ubuntu5.2
plucky

released

3.3.6-1.1ubuntu1
upstream

released

3.3.6

Показывать по

EPSS

Процентиль: 44%
0.00208
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
redhat
10 месяцев назад

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like REXML::Document.new, you may be impacted to this vulnerability. If you use other parser APIs such as stream parser API and SAX2 parser API, this vulnerability is not affected. The REXML gem 3.3.6 or later include the patch to fix the vulnerability.

CVSS3: 5.9
nvd
10 месяцев назад

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like REXML::Document.new, you may be impacted to this vulnerability. If you use other parser APIs such as stream parser API and SAX2 parser API, this vulnerability is not affected. The REXML gem 3.3.6 or later include the patch to fix the vulnerability.

CVSS3: 5.9
msrc
6 месяцев назад

Описание отсутствует

CVSS3: 5.9
debian
10 месяцев назад

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS ...

CVSS3: 5.9
github
10 месяцев назад

REXML denial of service vulnerability

EPSS

Процентиль: 44%
0.00208
Низкий

5.9 Medium

CVSS3

Уязвимость CVE-2024-43398