漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
REXML contains a denial of service vulnerability
Vulnerability Description
REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `<`s in an attribute value. Those who need to parse untrusted XMLs may be impacted to this vulnerability. The REXML gem 3.2.7 or later include the patch to fix this vulnerability. As a workaround, don't parse untrusted XMLs.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
Ruby 安全漏洞
Vulnerability Description
Ruby是松本行弘个人开发者的一种跨平台、面向对象的动态类型编程语言。 Ruby REXML 3.2.6 之前版本存在安全漏洞,该漏洞源于 REXML gem 在解析属性值中时存在拒绝服务漏洞。
CVSS Information
N/A
Vulnerability Type
N/A