CVE-2024-49761

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ruby-lang:rexml:*:*:*:*:*:ruby:*:*
cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:*

History

21 Mar 2025, 16:37

Type Values Removed Values Added
References () https://security.netapp.com/advisory/ntap-20241227-0004/ - () https://security.netapp.com/advisory/ntap-20241227-0004/ - Third Party Advisory
CPE cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:*
First Time Ruby-lang ruby
Netapp
Netapp ontap Tools

27 Dec 2024, 16:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20241227-0004/ -

Information

Published : 2024-10-28 15:15

Updated : 2025-03-21 16:37


NVD link : CVE-2024-49761

Mitre link : CVE-2024-49761

CVE.ORG link : CVE-2024-49761


JSON object : View

Products Affected

ruby-lang

  • ruby
  • rexml

netapp

  • ontap_tools
CWE
CWE-1333

Inefficient Regular Expression Complexity