CVE-2024-49761

HIGH

REXML <3.3.9 - ReDoS

Title source: llm
STIX 2.1

Description

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.

Scores

CVSS v3 7.5
EPSS 0.0169
EPSS Percentile 82.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-1333
Status published
Products (3)
netapp/ontap_tools 10
ruby-lang/rexml < 3.3.9
rubygems/rexml 0 - 3.3.9RubyGems
Published Oct 28, 2024
Tracked Since Feb 18, 2026