Publish GHSA-vmwr-mc7x-5vc3

This commit is contained in:
advisory-database[bot]
2024-08-28 20:09:39 +00:00
parent 3832052701
commit bbdc6f322c
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vmwr-mc7x-5vc3",
"modified": "2024-08-26T14:11:06Z",
"modified": "2024-08-28T20:08:14Z",
"published": "2024-08-22T16:40:46Z",
"aliases": [
"CVE-2024-43398"
],
"summary": "REXML denial of service vulnerability",
"details": "### Impact\n\nThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes.\n\nIf you need to parse untrusted XMLs with tree parser API like `REXML::Document.new`, you may be impacted to this vulnerability. If you use other parser APIs such as stream parser API and SAX2 parser API, this vulnerability is not affected.\n\n### Patches\n\nThe REXML gem 3.3.6 or later include the patch to fix the vulnerability.\n\n### Workarounds\n\nDon't parse untrusted XMLs with tree parser API.",
"details": "### Impact\n\nThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes.\n\nIf you need to parse untrusted XMLs with tree parser API like `REXML::Document.new`, you may be impacted to this vulnerability. If you use other parser APIs such as stream parser API and SAX2 parser API, this vulnerability is not affected.\n\n### Patches\n\nThe REXML gem 3.3.6 or later include the patch to fix the vulnerability.\n\n### Workarounds\n\nDon't parse untrusted XMLs with tree parser API.\n\n### References\n\n* https://www.ruby-lang.org/en/news/2024/08/22/dos-rexml-cve-2024-43398/ : An announce on www.ruby-lang.org\n",
"severity": [
{
"type": "CVSS_V3",
@@ -63,6 +63,10 @@
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rexml/CVE-2024-43398.yml"
},
{
"type": "WEB",
"url": "https://www.ruby-lang.org/en/news/2024/08/22/dos-rexml-cve-2024-43398"
}
],
"database_specific": {