REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like REXML::Document.new, you may be impacted to this vulnerability. If you use other parser APIs such as stream parser API and SAX2 parser API, this vulnerability is not affected. The REXML gem 3.3.6 or later include the patch to fix the vulnerability.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Sep 2024 06:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:enterprise_linux:8 cpe:/a:redhat:enterprise_linux:9 |
Tue, 17 Sep 2024 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat rhel E4s
Redhat rhel Eus Redhat rhel Tus |
|
CPEs | cpe:/a:redhat:rhel_e4s:8.6::highavailability cpe:/a:redhat:rhel_eus:8.8::highavailability cpe:/a:redhat:rhel_tus:8.6::highavailability |
|
Vendors & Products |
Redhat rhel E4s
Redhat rhel Eus Redhat rhel Tus |
Mon, 16 Sep 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat enterprise Linux |
|
CPEs | cpe:/a:redhat:enterprise_linux:8::highavailability | |
Vendors & Products |
Redhat
Redhat enterprise Linux |
Sat, 24 Aug 2024 03:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Thu, 22 Aug 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 22 Aug 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like REXML::Document.new, you may be impacted to this vulnerability. If you use other parser APIs such as stream parser API and SAX2 parser API, this vulnerability is not affected. The REXML gem 3.3.6 or later include the patch to fix the vulnerability. | |
Title | REXML denial of service vulnerability | |
Weaknesses | CWE-776 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-08-22T14:14:03.588Z
Updated: 2024-08-22T14:43:24.250Z
Reserved: 2024-08-12T18:02:04.965Z
Link: CVE-2024-43398
Vulnrichment
Updated: 2024-08-22T14:43:19.829Z
NVD
Status : Awaiting Analysis
Published: 2024-08-22T15:15:16.440
Modified: 2024-08-23T16:18:28.547
Link: CVE-2024-43398
Redhat