CVE-2024-49761

Published Oct 28, 2024

Last updated 9 months ago

Overview

Description
REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.
Source
security-advisories@github.com
NVD status
Modified
Products
rexml, ontap_tools

Risk scores

CVSS 4.0

Type
Secondary
Base score
6.6
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

Weaknesses

security-advisories@github.com
CWE-1333

Social media

Hype score
Not currently trending
  1. CVE-2024-49761: ReDoS vulnerability in REXML https://t.co/ACUmFHVSF0 #bugbounty #bugbountytips #bugbountytip

    @bountywriteups

    30 Nov 2024

    542 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  2. ⚑ CVE-2024-49761: ReDoS vulnerability in REXML πŸ‘¨πŸ»β€πŸ’» manun ➟ Internet Bug Bounty 🟧 Medium πŸ’° None πŸ”— https://t.co/CuGTMLWHtL #bugbounty #bugbountytips #cybersecurity #infosec https://t.co/6hWzm5uxhB

    @h1Disclosed

    30 Nov 2024

    473 Impressions

    0 Retweets

    6 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 Urgent #Update: Patch Your Ruby Applications for #CVE-2024-49761 Vulnerability https://t.co/YvdHLaJgnq

    @UndercodeNews

    5 Nov 2024

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2024-49761 REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;).... https://t.co/thOWCEwOTe

    @VulmonFeeds

    28 Oct 2024

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2024-49761 REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeri… https://t.co/YCZ57BbsAm

    @CVEnew

    28 Oct 2024

    319 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    1 Quote

  6. Ruby: CVE-2024-49761: ReDoS vulnerability in REXML https://t.co/IEyQ95qSz4 #rubylang #devtalk

    @dev_talk

    28 Oct 2024

    35 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    1 Quote

Configurations