REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.
References
Link | Resource |
---|---|
https://github.com/ruby/rexml/commit/ce59f2eb1aeb371fe1643414f06618dbe031979f | Patch |
https://github.com/ruby/rexml/security/advisories/GHSA-2rxp-v6pw-ch6m | Third Party Advisory |
https://www.ruby-lang.org/en/news/2024/10/28/redos-rexml-cve-2024-49761 | Vendor Advisory |
https://security.netapp.com/advisory/ntap-20241227-0004/ | Third Party Advisory |
Configurations
History
21 Mar 2025, 16:37
Type | Values Removed | Values Added |
---|---|---|
References | () https://security.netapp.com/advisory/ntap-20241227-0004/ - Third Party Advisory | |
CPE | cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:* |
|
First Time |
Ruby-lang ruby
Netapp Netapp ontap Tools |
27 Dec 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2024-10-28 15:15
Updated : 2025-03-21 16:37
NVD link : CVE-2024-49761
Mitre link : CVE-2024-49761
CVE.ORG link : CVE-2024-49761
JSON object : View
Products Affected
ruby-lang
- ruby
- rexml
netapp
- ontap_tools
CWE
CWE-1333
Inefficient Regular Expression Complexity