REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.
References
Configurations
History
03 Nov 2025, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Mar 2025, 16:37
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://security.netapp.com/advisory/ntap-20241227-0004/ - Third Party Advisory | |
| CPE | cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:* |
|
| First Time |
Ruby-lang ruby
Netapp Netapp ontap Tools |
27 Dec 2024, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Information
Published : 2024-10-28 15:15
Updated : 2025-11-03 21:16
NVD link : CVE-2024-49761
Mitre link : CVE-2024-49761
CVE.ORG link : CVE-2024-49761
JSON object : View
Products Affected
netapp
- ontap_tools
ruby-lang
- rexml
- ruby
CWE
CWE-1333
Inefficient Regular Expression Complexity
