• caglararli@hotmail.com
  • 05386281520

CVE-2024-43398 | rexml Gem up to 3.3.5 on Ruby API Parser REXML::Document.new xml entity expansion

Çağlar Arlı      -    11 Views

CVE-2024-43398 | rexml Gem up to 3.3.5 on Ruby API Parser REXML::Document.new xml entity expansion

A vulnerability classified as problematic has been found in rexml Gem up to 3.3.5 on Ruby. This affects the function REXML::Document.new of the component API Parser. The manipulation leads to xml entity expansion. This vulnerability is uniquely identified as CVE-2024-43398. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected component.