XML External Entity injection in Ruby and REXML - CVE-2021-28965
Published: April 8, 2021 / Updated: April 22, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied XML input. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.
Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.
Affected software
REXML
Arch Linux
Amazon Linux AMI
SUSE MicroOS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
Fedora
cflinuxfs3
IBM Cloud Foundry Migration Runtime
Red Hat Software Collections
Gitlab Community Edition
GitLab Enterprise Edition
ruby2.5 (Debian package)
ruby (Alpine package)
rh-ruby25-ruby (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
rubygem-net-telnet
rubygem-xmlrpc
rubygem-abrt-doc
rubygem-abrt
rubygem-io-console
rubygem-mysql2
rubygem-mysql2-doc
rubygem-yard
rubygem-pry
rubygem-power_assert
rubygem-did_you_mean
rubygem-pg-doc
rubygem-pg
rubygem-irb
rubygem-bigdecimal
rubygem-json
rubygem-openssl
rubygem-bundler
libruby2.3 (Ubuntu package)
ruby2.3 (Ubuntu package)
ruby2.5 (Ubuntu package)
libruby2.5 (Ubuntu package)
ruby-debuginfo
ruby-irb
ruby-help
ruby-debugsource
ruby-devel
ruby
ruby2.5-devel-extra
libruby2_5-2_5-debuginfo
ruby2.5
ruby2.5-debuginfo
ruby2.5-debugsource
libruby2_5-2_5
ruby2.5-stdlib
ruby2.5-stdlib-debuginfo
ruby2.5-devel
rh-ruby26-ruby (Red Hat package)
libruby2.7 (Ubuntu package)
ruby2.7 (Ubuntu package)
rh-ruby27-ruby (Red Hat package)
ruby-doc
ruby-default-gems
ruby-libs
rubygems
rubygems-devel
rubygem-mongo
rubygem-mongo-doc
rubygem-psych
rubygem-test-unit
rubygem-bson-doc
rubygem-bson
rubygem-minitest
rubygem-rdoc
rubygem-railties
rubygem-rake
Netcool Operations Insight
How to mitigate CVE-2021-28965
REXML - update to 3.2.5
cflinuxfs3 - update to 0.236.0
ruby2.5 (Debian package) - update to 2.5.5-3+deb10u4
ruby (Alpine package) - update to 2.7.3-r0
rh-ruby25-ruby (Red Hat package) - update to 2.5.9-9.el7
IBM Cloud Foundry Migration Runtime - update to 4.1.2
Gitlab Community Edition - addressed in versions 13.8.8, 13.9.6, 13.10.3
GitLab Enterprise Edition - addressed in versions 13.8.8, 13.9.6, 13.10.3
rubygem-net-telnet - update to 0.1.1-113
rubygem-net-telnet - update to 0.2.0-136
rubygem-xmlrpc - update to 0.3.0-113
rubygem-xmlrpc - update to 0.3.0-136
rubygem-abrt-doc - update to 0.4.0-1
rubygem-abrt - update to 0.4.0-1
rubygem-io-console - update to 0.4.6-113
rubygem-mysql2 - update to 0.5.3-1
rubygem-mysql2-doc - update to 0.5.3-1
rubygem-io-console - update to 0.5.6-136
rubygem-yard - update to 0.9.26-3.fc34
rubygem-pry - update to 0.13.1-5.fc34
rubygem-power_assert - update to 1.1.1-113
rubygem-power_assert - update to 1.1.7-136
rubygem-did_you_mean - update to 1.2.0-113
rubygem-pg-doc - update to 1.2.3-1.0.1
rubygem-pg - update to 1.2.3-1.0.1
rubygem-irb - update to 1.2.6-136
rubygem-bigdecimal - update to 1.3.4-113
Netcool Operations Insight - update to 1.6.10
rubygem-bigdecimal - update to 2.0.0-136
rubygem-json - update to 2.1.0-113
rubygem-openssl - update to 2.1.2-113
rubygem-openssl - update to 2.1.2-136
rubygem-bundler - update to 2.1.4-136
rubygem-json - update to 2.3.0-136
libruby2.3 (Ubuntu package) - update to 2.3.1-2~ubuntu16.04.16
ruby2.3 (Ubuntu package) - update to 2.3.1-2~ubuntu16.04.16
ruby2.5 (Ubuntu package) - update to 2.5.1-1ubuntu1.9
libruby2.5 (Ubuntu package) - update to 2.5.1-1ubuntu1.9
ruby-debuginfo - update to 2.5.8-113
ruby-irb - update to 2.5.8-113
ruby-help - update to 2.5.8-113
ruby-debugsource - update to 2.5.8-113
ruby-devel - update to 2.5.8-113
ruby - update to 2.5.8-113
ruby2.5-devel-extra - update to 2.5.9-4.17.1
libruby2_5-2_5-debuginfo - update to 2.5.9-4.17.1
ruby2.5 - update to 2.5.9-4.17.1
ruby2.5-debuginfo - update to 2.5.9-4.17.1
ruby2.5-debugsource - update to 2.5.9-4.17.1
libruby2_5-2_5 - update to 2.5.9-4.17.1
ruby2.5-stdlib - update to 2.5.9-4.17.1
ruby2.5-stdlib-debuginfo - update to 2.5.9-4.17.1
ruby2.5-devel - update to 2.5.9-4.17.1
rh-ruby26-ruby (Red Hat package) - update to 2.6.7-119.el7
libruby2.7 (Ubuntu package) - addressed in versions 2.7.0-5ubuntu1.4, 2.7.1-3ubuntu1.3, 2.7.2-4ubuntu1.1
ruby2.7 (Ubuntu package) - addressed in versions 2.7.0-5ubuntu1.4, 2.7.1-3ubuntu1.3, 2.7.2-4ubuntu1.1
rh-ruby27-ruby (Red Hat package) - update to 2.7.3-129.el7
ruby-doc - update to 2.7.3-136
ruby-default-gems - update to 2.7.3-136
ruby-libs - update to 2.7.3-136
ruby-devel - update to 2.7.3-136
ruby - update to 2.7.3-136
ruby - addressed in versions 2.7.3-136.fc32, 2.7.3-136.fc33, 2.7-3320210609104615.601d93de, 2.7-3420210609104615.058368ca, 3.0.1-148.fc34
rubygems - update to 2.7.6-113
rubygems-devel - update to 2.7.6-113
rubygem-mongo - update to 2.11.3-1
rubygem-mongo-doc - update to 2.11.3-1
rubygem-psych - update to 3.0.2-113
rubygem-psych - update to 3.1.0-136
rubygems - update to 3.1.6-136
rubygems-devel - update to 3.1.6-136
rubygem-test-unit - update to 3.2.7-113
rubygem-test-unit - update to 3.3.4-136
rubygem-bson-doc - update to 4.8.1-1
rubygem-bson - update to 4.8.1-1
rubygem-minitest - update to 5.10.3-113
rubygem-minitest - update to 5.13.0-136
rubygem-rdoc - update to 6.0.1.1-113
rubygem-railties - update to 6.1.2.1-2.fc34
rubygem-rdoc - update to 6.2.1-136
rubygem-rake - update to 12.3.0-113
rubygem-rake - update to 13.0.1-136
External References
Related Security Bulletins
- XML External Entity injection in REXML gem for Ruby
- XML External Entity injection in ruby (Alpine package)
- XML External Entity injection in Cloud Foundry cflinuxfs3
- Multiple vulnerabilities in GitLab
- Arch Linux update for gitlab
- Amazon Linux AMI update for ruby24
- Red Hat Software Collections update for rh-ruby25-ruby
- Red Hat Software Collections update for rh-ruby27-ruby
- Red Hat Software Collections update for rh-ruby26-ruby
- Red Hat Enterprise Linux 8 update for the ruby:2.7 module
- Red Hat Enterprise Linux 8 update for the ruby:2.5 module
- Red Hat Enterprise Linux 8 update for the ruby:2.6 module
- Debian update for ruby2.5
- Red Hat Enterprise Linux 8.1 update for the ruby:2.6 module
- Red Hat Enterprise Linux 8.2 update for the ruby:2.6 module
- SUSE update for ruby2.5
- Ubuntu update for ruby2.3
- Ubuntu update for ruby2.7
- Multiple vulnerabilities in IBM Cloud Foundry Migration Runtime
- Multiple vulnerabilities in Netcool Operations Insight
- openEuler 20.03 LTS SP1 update for ruby
- Fedora 34 update for ruby, rubygem-pry, rubygem-railties, rubygem-yard
- Fedora 33 update for ruby
- Fedora 32 update for ruby
- Fedora 34 Modular update for ruby
- Fedora 33 Modular update for ruby
- Anolis OS update for ruby:2.7 module