V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2024-43398
ANC
Medium

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that…

CVSS
5.9
Medium
EPSS
0.01
p64
Published
2024-01-01
Updated
2024-01-01
Description

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like REXML::Document.new, you may be impacted to this vulnerability. If you use other parser APIs such as stream parser API and SAX2 parser API, this vulnerability is not affected. The REXML gem 3.3.6 or later include the patch to fix the vulnerability.

Tags · CWE
Pre-auth
CWE-776
CAPEC-197
Affected products
Rexml < 3.3.6
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Timeline
2024-01-01
Published
2024-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.012 · p64
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
Tracked
pcsTracked
pcsTracked
pcsTracked
pcsTracked
rubyTracked
rubyTracked
ruby2.7Tracked
ruby2.7Tracked
ruby3.0Tracked
ruby3.1Tracked
ruby3.1Tracked
ruby3.2Tracked
ruby3.2Tracked
ruby3.3Tracked
ruby3.3Tracked
ruby3.3Tracked
ruby3.3Tracked
bootstrap_os*Tracked
rexml*Tracked
Source databases
ANC
DEB
CVE
RED
UBU
Related vulnerabilities