CVE-2024-41123

R

EXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, `>]` and `]>`. The REXML gem 3.3.3 or later include the patches to fix these vulnerabilities.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ruby-lang:rexml:*:*:*:*:*:ruby:*:*
cpe:2.3:a:ruby-lang:rexml:*:*:*:*:*:ruby:*:*

History

03 Nov 2025, 21:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html -

27 Dec 2024, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 5.3
References
  • () https://security.netapp.com/advisory/ntap-20241227-0005/ -

05 Sep 2024, 16:12

Type Values Removed Values Added
First Time Ruby-lang
Ruby-lang rexml
CPE cpe:2.3:a:ruby-lang:rexml:*:*:*:*:*:ruby:*:*
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 7.5
References () https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8 - () https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8 - Not Applicable
References () https://github.com/ruby/rexml/security/advisories/GHSA-r55c-59qm-vjw6 - () https://github.com/ruby/rexml/security/advisories/GHSA-r55c-59qm-vjw6 - Vendor Advisory
References () https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh - () https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh - Not Applicable
References () https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41123 - () https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41123 - Vendor Advisory

01 Aug 2024, 16:45

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-01 15:15

Updated : 2025-11-03 21:16


NVD link : CVE-2024-41123

Mitre link : CVE-2024-41123

CVE.ORG link : CVE-2024-41123


JSON object : View

Products Affected
CWE
CWE-400

Uncontrolled Resource Consumption