Search CVE reports
11 – 12 of 12 results
CVE-2024-39908
Medium prioritySome fixes available 4 of 13
REXML is an XML toolkit for Ruby. The REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as `<`, `0` and `%>`. If you need to parse untrusted XMLs, you many be impacted...
7 affected packages
jruby, ruby2.3, ruby2.5, ruby2.7, ruby3.0...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
jruby | Needs evaluation | Not in release | Needs evaluation | Needs evaluation |
ruby2.3 | Not in release | Not in release | Not in release | — |
ruby2.5 | Not in release | Not in release | Not in release | Vulnerable |
ruby2.7 | Not in release | Not in release | Fixed | — |
ruby3.0 | Not in release | Fixed | Not in release | — |
ruby3.2 | Fixed | Not in release | Not in release | — |
ruby3.3 | Not in release | Not in release | Not in release | — |
CVE-2024-35176
Medium prioritySome fixes available 3 of 12
REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `<`s in an attribute value. Those who need to parse untrusted XMLs may be impacted to this...
7 affected packages
jruby, ruby2.3, ruby2.5, ruby2.7, ruby3.0...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
jruby | Needs evaluation | Not in release | Needs evaluation | Needs evaluation |
ruby2.3 | Not in release | Not in release | Not in release | — |
ruby2.5 | Not in release | Not in release | Not in release | Vulnerable |
ruby2.7 | Not in release | Not in release | Fixed | — |
ruby3.0 | Not in release | Fixed | Not in release | — |
ruby3.2 | Fixed | Not in release | Not in release | — |
ruby3.3 | Not in release | Not in release | Not in release | — |