Description
REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, `>]` and `]>`. The REXML gem 3.3.3 or later include the patches to fix these vulnerabilities.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4018-1 | ruby2.7 security update |
EUVD |
EUVD-2024-2644 | REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, `>]` and `]>`. The REXML gem 3.3.3 or later include the patches to fix these vulnerabilities. |
Github GHSA |
GHSA-r55c-59qm-vjw6 | REXML DoS vulnerability |
Ubuntu USN |
USN-7091-1 | Ruby vulnerabilities |
Ubuntu USN |
USN-7091-2 | Ruby vulnerabilities |
Ubuntu USN |
USN-7418-1 | Ruby vulnerabilities |
Ubuntu USN |
USN-7840-1 | Ruby vulnerabilities |
References
History
Mon, 03 Nov 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 27 Dec 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 19 Sep 2024 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:enterprise_linux:8 cpe:/a:redhat:enterprise_linux:9 |
Tue, 17 Sep 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhel E4s
Redhat rhel Eus Redhat rhel Tus |
|
| CPEs | cpe:/a:redhat:rhel_e4s:8.6::highavailability cpe:/a:redhat:rhel_eus:8.8::highavailability cpe:/a:redhat:rhel_tus:8.6::highavailability |
|
| Vendors & Products |
Redhat rhel E4s
Redhat rhel Eus Redhat rhel Tus |
Mon, 16 Sep 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| CPEs | cpe:/a:redhat:enterprise_linux:8::highavailability | |
| Vendors & Products |
Redhat
Redhat enterprise Linux |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-03T20:38:32.688Z
Reserved: 2024-07-15T15:53:28.323Z
Link: CVE-2024-41123
Updated: 2024-12-27T16:03:05.085Z
Status : Modified
Published: 2024-08-01T15:15:13.213
Modified: 2025-11-03T21:16:17.383
Link: CVE-2024-41123
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA
Ubuntu USN