[MAVEN:GHSA-HGG7-CGHQ-XHF4] Ruby vulnerable to denial of service

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

When reading text nodes from an XML document, the REXML parser can be coerced in to allocating extremely large string objects which can consume all of the memory on a machine, causing a denial of service.

Jruby resolves this bug in version 1.7.3 as noted in https://www.jruby.org/2013/02/21/jruby-1-7-3.html

Package Affected Version
pkg:maven/org.jruby/jruby < 1.7.3
Package Fixed Version
pkg:maven/org.jruby/jruby = 1.7.3
ID
MAVEN:GHSA-HGG7-CGHQ-XHF4
Severity
moderate
URL
https://github.com/advisories/GHSA-hgg7-cghq-xhf4
Published
2022-05-17T03:23:26
(2 years ago)
Modified
2023-08-16T09:36:13
(13 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jruby/jruby org.jruby jruby < 1.7.3
Fixed pkg:maven/org.jruby/jruby org.jruby jruby = 1.7.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...