CVE-2024-41123

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, `>]` and `]>`. The REXML gem 3.3.3 or later include the patches to fix these vulnerabilities.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ruby-lang:rexml:*:*:*:*:*:ruby:*:*
cpe:2.3:a:ruby-lang:rexml:*:*:*:*:*:ruby:*:*

History

27 Dec 2024, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 5.3
References
  • () https://security.netapp.com/advisory/ntap-20241227-0005/ -

05 Sep 2024, 16:12

Type Values Removed Values Added
CPE cpe:2.3:a:ruby-lang:rexml:*:*:*:*:*:ruby:*:*
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 7.5
First Time Ruby-lang rexml
Ruby-lang
References () https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8 - () https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8 - Not Applicable
References () https://github.com/ruby/rexml/security/advisories/GHSA-r55c-59qm-vjw6 - () https://github.com/ruby/rexml/security/advisories/GHSA-r55c-59qm-vjw6 - Vendor Advisory
References () https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh - () https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh - Not Applicable
References () https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41123 - () https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41123 - Vendor Advisory
Summary
  • (es) REXML es un conjunto de herramientas XML para Ruby. La gema REXML anterior a 3.3.2 tiene algunas vulnerabilidades DoS cuando analiza un XML que tiene muchos caracteres específicos, como espacios en blanco, `>]` y `]>`. La gema REXML 3.3.3 o posterior incluye los parches para corregir estas vulnerabilidades.

01 Aug 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-01 15:15

Updated : 2024-12-27 16:15


NVD link : CVE-2024-41123

Mitre link : CVE-2024-41123

CVE.ORG link : CVE-2024-41123


JSON object : View

Products Affected

ruby-lang

  • rexml
CWE
CWE-400

Uncontrolled Resource Consumption