CVE-2024-43398
Last modified
CVE-2024-43398 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. EPSS estimates a 1.21% chance of exploitation in the next 30 days.
Description
REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like REXML::Document.new, you may be impacted to this vulnerability. If you use other parser APIs such as stream parser API and SAX2 parser API, this vulnerability is not affected. The REXML gem 3.3.6 or later include the patch to fix the vulnerability.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ruby-Lang | Rexml | < 3.3.6 |
| Netapp | Bootstrap Os | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-43398?
How severe is CVE-2024-43398?
How do I fix CVE-2024-43398?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-43392A low privileged remote attacker can perform configuration c…8.1
- CVE-2024-43393A low privileged remote attacker can perform configuration c…8.1
- CVE-2024-43394Server-Side Request Forgery (SSRF) in Apache HTTP Server on …7.5
- CVE-2024-43395CraftOS-PC 2 is a rewrite of the desktop port of CraftOS fro…8.2
- CVE-2024-43396Khoj is an application that creates personal AI agents. The …5.4
- CVE-2024-43397Apollo is a configuration management system. A vulnerability…4.3
- CVE-2024-43399Mobile Security Framework (MobSF) is a pen-testing, malware …9.8
- CVE-2024-4340Passing a heavily nested list to sqlparse.parse() leads to a…7.5
- CVE-2024-43400XWiki Platform is a generic wiki platform offering runtime s…5.4
- CVE-2024-43401XWiki Platform is a generic wiki platform offering runtime s…8
- CVE-2024-43402Rust is a programming language. The fix for CVE-2024-24576, …8.8
- CVE-2024-43403Kanister is a data protection workflow management tool. The …8.8
Are you affected by CVE-2024-43398?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
