Denial of Service Vulnerability in REXML XML Toolkit for Ruby
CVE-2024-41123
What is CVE-2024-41123?
The REXML gem, an XML processing library in Ruby, is susceptible to Denial of Service (DoS) vulnerabilities in versions prior to 3.3.2 due to its method of parsing XML documents containing specific character sequences, such as whitespace, ]>, and > characters. Attackers can leverage these vulnerabilities by crafting malicious XML inputs that exploit these weaknesses, potentially leading to service disruptions. Versions 3.3.3 and later of the REXML gem address these vulnerabilities through crucial patches, enhancing the security and stability of applications relying on this toolkit.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
rexml < 3.3.3
References
CVSS V3.1
Timeline
Vulnerability published
