VulnerabilityModified
CVE-2024-41123
The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, `>]` and `]>`.
HIGH 7.5EPSS 1.28%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, `>]` and `]>`. The REXML gem 3.3.3 or later include the patches to fix these vulnerabilities.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.28% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- ruby-lang/rexml
- Source
- security-advisories@github.com
References
- https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8Not Applicable
- https://github.com/ruby/rexml/security/advisories/GHSA-r55c-59qm-vjw6Vendor Advisory
- https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xghNot Applicable
- https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41123Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html
- https://security.netapp.com/advisory/ntap-20241227-0005/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.