REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `<`s in an attribute value. Those who need to parse untrusted XMLs may be impacted to this vulnerability. The REXML gem 3.2.7 or later include the patch to fix this vulnerability. As a workaround, don't parse untrusted XMLs.
History

Fri, 16 Aug 2024 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:8::highavailability

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-05-16T15:13:25.100Z

Updated: 2024-08-02T03:07:46.804Z

Reserved: 2024-05-10T14:24:24.338Z

Link: CVE-2024-35176

cve-icon Vulnrichment

Updated: 2024-05-16T18:27:28.936Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-16T16:15:09.707

Modified: 2024-05-17T18:36:31.297

Link: CVE-2024-35176

cve-icon Redhat

Severity : Low

Publid Date: 2024-05-16T00:00:00Z

Links: CVE-2024-35176 - Bugzilla