• CVE-2024-49761

发布时间: 2024年11月8日

修改时间: 2024年11月8日

概要

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.

CVSS v3 指标

NVD openEuler
Confidentiality None
Attack Vector Network
CVSS评分 N/A 6.5
Attack Complexity Low
Privileges Required None
Scope Unchanged
Integrity None
User Interaction Required
Availability High

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-4191 ruby security update 2025年2月8日

影响产品

产品 状态
KY3.4-5A ruby Fixed
KY3.5.2 ruby Fixed
KY3.5.3 ruby Fixed
V6 ruby Fixed