VDB
Sign up
MEDIUM5.9

GHSA-vmwr-mc7x-5vc3

REXML denial of service vulnerability

Quick fix

GHSA-vmwr-mc7x-5vc3 — rexml: upgrade to the fixed version with the command below.

bundle update rexml

Details

### Impact

The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes.

If you need to parse untrusted XMLs with tree parser API like `REXML::Document.new`, you may be impacted to this vulnerability. If you use other parser APIs such as stream parser API and SAX2 parser API, this vulnerability is not affected.

### Patches

The REXML gem 3.3.6 or later include the patch to fix the vulnerability.

### Workarounds

Don't parse untrusted XMLs with tree parser API.

### References

* https://www.ruby-lang.org/en/news/2024/08/22/dos-rexml-cve-2024-43398/ : An announce on www.ruby-lang.org

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rexml
Introduced in: 0Fixed in: 3.3.6
Fixbundle update rexml

References