vulnerability
Red Hat: CVE-2024-35176: REXML: DoS parsing an XML with many `<`s in an attribute value (Multiple Advisories)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
5 | (AV:N/AC:L/Au:N/C:N/I:N/A:P) | 05/16/2024 | 07/16/2024 | 09/13/2024 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
05/16/2024
Added
07/16/2024
Modified
09/13/2024
Description
REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `
Solution(s)
redhat-upgrade-pcsredhat-upgrade-pcs-snmpredhat-upgrade-rubyredhat-upgrade-ruby-debuginforedhat-upgrade-ruby-debugsourceredhat-upgrade-ruby-develredhat-upgrade-ruby-docredhat-upgrade-ruby-irbredhat-upgrade-ruby-libsredhat-upgrade-ruby-libs-debuginforedhat-upgrade-rubygem-abrtredhat-upgrade-rubygem-abrt-docredhat-upgrade-rubygem-bigdecimalredhat-upgrade-rubygem-bigdecimal-debuginforedhat-upgrade-rubygem-bsonredhat-upgrade-rubygem-bson-debuginforedhat-upgrade-rubygem-bson-debugsourceredhat-upgrade-rubygem-bson-docredhat-upgrade-rubygem-bundlerredhat-upgrade-rubygem-bundler-docredhat-upgrade-rubygem-did_you_meanredhat-upgrade-rubygem-io-consoleredhat-upgrade-rubygem-io-console-debuginforedhat-upgrade-rubygem-jsonredhat-upgrade-rubygem-json-debuginforedhat-upgrade-rubygem-minitestredhat-upgrade-rubygem-mongoredhat-upgrade-rubygem-mongo-docredhat-upgrade-rubygem-mysql2redhat-upgrade-rubygem-mysql2-debuginforedhat-upgrade-rubygem-mysql2-debugsourceredhat-upgrade-rubygem-mysql2-docredhat-upgrade-rubygem-net-telnetredhat-upgrade-rubygem-opensslredhat-upgrade-rubygem-openssl-debuginforedhat-upgrade-rubygem-pgredhat-upgrade-rubygem-pg-debuginforedhat-upgrade-rubygem-pg-debugsourceredhat-upgrade-rubygem-pg-docredhat-upgrade-rubygem-power_assertredhat-upgrade-rubygem-psychredhat-upgrade-rubygem-psych-debuginforedhat-upgrade-rubygem-rakeredhat-upgrade-rubygem-rdocredhat-upgrade-rubygem-test-unitredhat-upgrade-rubygem-xmlrpcredhat-upgrade-rubygemsredhat-upgrade-rubygems-devel

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.