216.73.217.22

CVE-2024-49761

· Published 28/10/2024 15:15 · Modified 05/11/2024 16:41

Labels: CVE-2024-49761 2024-10-28CVE-2024-49761CWE-1333[email protected]

Essential information

Published
28/10/2024 15:15
Modified
05/11/2024 16:41
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS metrics

Description

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ruby-lang / rexml cpe:2.3:a:ruby-lang:rexml:*:*:*:*:*:ruby:*:*

References