[RUBYSEC:REXML-2021-28965] XML round-trip vulnerability in REXML

Severity High
Affected Packages 1
Fixed Packages 3
CVEs 1

When parsing and serializing a crafted XML document, REXML gem (including
the one bundled with Ruby) can create a wrong XML document whose structure
is different from the original one.

Package Affected Version
pkg:gem/rexml < 3.2.5
Package Fixed Version
pkg:gem/rexml = 3.1.9.1
pkg:gem/rexml = 3.2.3.1
pkg:gem/rexml >= 3.2.5
Source # ID Name URL
Security Advisory GHSA-8cr8-4vfw-mr7h https://github.com/advisories/GHSA-8cr8-4vfw-mr7h
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:gem/rexml rexml = 3.1.9.1
Fixed pkg:gem/rexml rexml = 3.2.3.1
Fixed pkg:gem/rexml rexml >= 3.2.5
Affected pkg:gem/rexml rexml < 3.2.5
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...