Логотип exploitDog
bind:CVE-2024-49761
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-49761

Количество 14

Количество 14

ubuntu логотип

CVE-2024-49761

8 месяцев назад

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-49761

8 месяцев назад

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-49761

8 месяцев назад

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2024-49761

7 месяцев назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-49761

8 месяцев назад

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReD ...

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20241112-06

7 месяцев назад

Уязвимость rubygem-rexml

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rxp-v6pw-ch6m

8 месяцев назад

REXML ReDoS vulnerability

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2024-10860

7 месяцев назад

ELSA-2024-10860: ruby:3.1 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10858

7 месяцев назад

ELSA-2024-10858: ruby security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10850

7 месяцев назад

ELSA-2024-10850: ruby:2.5 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10834

7 месяцев назад

ELSA-2024-10834: ruby:3.1 security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2024-09876

8 месяцев назад

Уязвимость набора инструментов XML для Ruby REXML, связанная с использованием регулярного выражения c неэффективной вычислительной сложностью, позволяющая нарушителю выполнить атаку типа «отказ в обслуживании»

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0736-1

4 месяца назад

Security update for ruby2.5

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:0129-1

2 месяца назад

Security update for rubygem-rexml

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-49761

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
redhat логотип
CVE-2024-49761

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2024-49761

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
msrc логотип
CVSS3: 7.5
0%
Низкий
7 месяцев назад
debian логотип
CVE-2024-49761

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReD ...

CVSS3: 7.5
0%
Низкий
8 месяцев назад
redos логотип
ROS-20241112-06

Уязвимость rubygem-rexml

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-2rxp-v6pw-ch6m

REXML ReDoS vulnerability

CVSS3: 7.5
0%
Низкий
8 месяцев назад
oracle-oval логотип
ELSA-2024-10860

ELSA-2024-10860: ruby:3.1 security update (IMPORTANT)

7 месяцев назад
oracle-oval логотип
ELSA-2024-10858

ELSA-2024-10858: ruby security update (IMPORTANT)

7 месяцев назад
oracle-oval логотип
ELSA-2024-10850

ELSA-2024-10850: ruby:2.5 security update (IMPORTANT)

7 месяцев назад
oracle-oval логотип
ELSA-2024-10834

ELSA-2024-10834: ruby:3.1 security update (IMPORTANT)

7 месяцев назад
fstec логотип
BDU:2024-09876

Уязвимость набора инструментов XML для Ruby REXML, связанная с использованием регулярного выражения c неэффективной вычислительной сложностью, позволяющая нарушителю выполнить атаку типа «отказ в обслуживании»

CVSS3: 7.5
0%
Низкий
8 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0736-1

Security update for ruby2.5

4 месяца назад
suse-cvrf логотип
openSUSE-SU-2025:0129-1

Security update for rubygem-rexml

2 месяца назад

Уязвимостей на страницу