The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5066-1 | ruby2.5 security update |
EUVD |
EUVD-2021-0797 | The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing. |
Github GHSA |
GHSA-8cr8-4vfw-mr7h | REXML round-trip instability |
Ubuntu USN |
USN-4922-1 | Ruby vulnerability |
Ubuntu USN |
USN-4922-2 | Ruby vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T21:55:12.192Z
Reserved: 2021-03-22T00:00:00
Link: CVE-2021-28965
No data.
Status : Modified
Published: 2021-04-21T07:15:07.677
Modified: 2024-11-21T06:00:27.733
Link: CVE-2021-28965
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Github GHSA
Ubuntu USN