Skip to content

Commit

Permalink
Add CVE-2024-41946: DoS vulnerability in REXML
Browse files Browse the repository at this point in the history
  • Loading branch information
kou authored and hsbt committed Aug 1, 2024
1 parent 552a3c0 commit 11a15d6
Showing 1 changed file with 29 additions and 0 deletions.
29 changes: 29 additions & 0 deletions en/news/_posts/2024-08-01-dos-rexml-cve-2024-41946.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
---
layout: news_post
title: "CVE-2024-41946: DoS vulnerability in REXML"
author: "kou"
translator:
date: 2024-08-01 03:00:00 +0000
tags: security
lang: en
---

There is a DoS vulnerability in REXML gem. This vulnerability has been assigned the CVE identifier [CVE-2024-41946](https://www.cve.org/CVERecord?id=CVE-2024-41946). We strongly recommend upgrading the REXML gem.

## Details

When parsing an XML that has many entity expansions with SAX2 or pull parser API, REXML gem may take long time.

Please update REXML gem to version 3.3.3 or later.

## Affected versions

* REXML gem 3.3.2 or prior

## Credits

Thanks to [NAITOH Jun](https://github.com/naitoh) for discovering and fixing this issue.

## History

* Originally published at 2024-08-01 03:00:00 (UTC)

0 comments on commit 11a15d6

Please sign in to comment.