Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-41946


REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. The REXML gem 3.3.3 or later include the patch to fix the vulnerability.


Published

2024-08-01T15:15:14.100

Last Modified

2025-01-17T20:15:28.380

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-400
  • Type: Primary
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ruby-lang rexml < 3.3.3 Yes

References