CVE-2024-35176

CVSS V2 None CVSS V3 None
Description
REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `<`s in an attribute value. Those who need to parse untrusted XMLs may be impacted to this vulnerability. The REXML gem 3.2.7 or later include the patch to fix this vulnerability. As a workaround, don't parse untrusted XMLs.
Overview
  • CVE ID
  • CVE-2024-35176
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-05-16T15:13:25.100Z
  • Last Modified Date
  • 2024-06-04T17:33:25.049Z
History
Created Old Value New Value Data Type Notes
2024-06-26 13:32:10 Added to TrackCVE