REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. The REXML gem 3.3.3 or later include the patch to fix the vulnerability.
History

Thu, 19 Sep 2024 06:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:8
cpe:/a:redhat:enterprise_linux:9

Tue, 17 Sep 2024 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel E4s
Redhat rhel Eus
Redhat rhel Tus
CPEs cpe:/a:redhat:rhel_e4s:8.6::highavailability
cpe:/a:redhat:rhel_eus:8.8::highavailability
cpe:/a:redhat:rhel_tus:8.6::highavailability
Vendors & Products Redhat rhel E4s
Redhat rhel Eus
Redhat rhel Tus

Mon, 16 Sep 2024 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:8::highavailability
Vendors & Products Redhat
Redhat enterprise Linux

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-08-01T14:22:14.014Z

Updated: 2024-08-01T15:50:11.993Z

Reserved: 2024-07-24T16:51:40.948Z

Link: CVE-2024-41946

cve-icon Vulnrichment

Updated: 2024-08-01T15:46:03.129Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-01T15:15:14.100

Modified: 2024-09-05T16:09:45.503

Link: CVE-2024-41946

cve-icon Redhat

Severity : Low

Publid Date: 2024-08-01T00:00:00Z

Links: CVE-2024-41946 - Bugzilla