vulnerability
Alma Linux: CVE-2024-49761: Important: ruby:3.1 security update (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:N/I:N/A:C) | Oct 28, 2024 | Dec 10, 2024 | Apr 20, 2026 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Oct 28, 2024
Added
Dec 10, 2024
Modified
Apr 20, 2026
Description
REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.
Solutions
alma-upgrade-pcsalma-upgrade-pcs-snmpalma-upgrade-rubyalma-upgrade-ruby-bundled-gemsalma-upgrade-ruby-default-gemsalma-upgrade-ruby-develalma-upgrade-ruby-docalma-upgrade-ruby-irbalma-upgrade-ruby-libsalma-upgrade-rubygem-abrtalma-upgrade-rubygem-abrt-docalma-upgrade-rubygem-bigdecimalalma-upgrade-rubygem-bsonalma-upgrade-rubygem-bson-docalma-upgrade-rubygem-bundleralma-upgrade-rubygem-bundler-docalma-upgrade-rubygem-did_you_meanalma-upgrade-rubygem-io-consolealma-upgrade-rubygem-irbalma-upgrade-rubygem-jsonalma-upgrade-rubygem-minitestalma-upgrade-rubygem-mongoalma-upgrade-rubygem-mongo-docalma-upgrade-rubygem-mysql2alma-upgrade-rubygem-mysql2-docalma-upgrade-rubygem-net-telnetalma-upgrade-rubygem-opensslalma-upgrade-rubygem-pgalma-upgrade-rubygem-pg-docalma-upgrade-rubygem-power_assertalma-upgrade-rubygem-psychalma-upgrade-rubygem-rakealma-upgrade-rubygem-rbsalma-upgrade-rubygem-rdocalma-upgrade-rubygem-rexmlalma-upgrade-rubygem-rssalma-upgrade-rubygem-test-unitalma-upgrade-rubygem-typeprofalma-upgrade-rubygem-xmlrpcalma-upgrade-rubygemsalma-upgrade-rubygems-devel
References
- CVE-2024-49761
- https://attackerkb.com/topics/CVE-2024-49761
- CWE-1333
- EUVD-EUVD-2024-2910
- https://errata.almalinux.org/8/ALSA-2024-10834.html
- https://errata.almalinux.org/8/ALSA-2024-10850.html
- https://errata.almalinux.org/8/ALSA-2025-11047.html
- https://errata.almalinux.org/9/ALSA-2024-10858.html
- https://errata.almalinux.org/9/ALSA-2024-10860.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-2910
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.