DirectorySecurity Advisories
Sign In
Security Advisories

CGA-35f5-2796-7j5c

Published

Last updated

https://images.chainguard.dev/security/CGA-35f5-2796-7j5c
Package

ruby-3.1

Latest Update
Fixed
Fixed Version

3.1.6-r6

Aliases
  • CVE-2024-49761
  • GHSA-2rxp-v6pw-ch6m

Severity

7.5

High

CVSS V3

Summary

REXML ReDoS vulnerability

Description

Impact

The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;).

This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03.

Patches

The REXML gem 3.3.9 or later include the patch to fix the vulnerability.

Workarounds

Use Ruby 3.2 or later instead of Ruby 3.1.

References

  • https://www.ruby-lang.org/en/news/2024/10/28/redos-rexml-cve-2024-49761/: An announce on www.ruby-lang.org

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images