REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `<`s in an attribute value. Those who need to parse untrusted XMLs may be impacted to this vulnerability. The REXML gem 3.2.7 or later include the patch to fix this vulnerability. As a workaround, don't parse untrusted XMLs.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-05-16T15:13:25.100Z

Updated: 2024-06-04T17:33:25.049Z

Reserved: 2024-05-10T14:24:24.338Z


Link: CVE-2024-35176

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-05-16T16:15:09.707

Modified: 2024-05-17T18:36:31.297


Link: CVE-2024-35176

JSON object: View

cve-icon Redhat Information

No data.