CVE-2024-49761

HIGH

REXML < 3.3.9 - Inefficient Regular Expression Complexity in Hex Numeric Character Reference Parsing

Title source: llm
STIX 2.1

Description

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.

Scores

CVSS v3 7.5
EPSS 0.0143
EPSS Percentile 69.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-1333
Status published
Products (3)
netapp/ontap_tools 10
ruby-lang/rexml < 3.3.9
rubygems/rexml 0 - 3.3.9RubyGems
Published Oct 28, 2024
Tracked Since Feb 18, 2026