XML External Entity injection in Ruby and REXML - CVE-2021-28965

 

XML External Entity injection in Ruby and REXML - CVE-2021-28965

Published: April 8, 2021 / Updated: April 22, 2021


Vulnerability identifier: #VU52000
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28965
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied XML input. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.

Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.


Affected software

Ruby
REXML
Arch Linux
Amazon Linux AMI
SUSE MicroOS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
Fedora
cflinuxfs3
IBM Cloud Foundry Migration Runtime
Red Hat Software Collections
Gitlab Community Edition
GitLab Enterprise Edition
ruby2.5 (Debian package)
ruby (Alpine package)
rh-ruby25-ruby (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
rubygem-net-telnet
rubygem-xmlrpc
rubygem-abrt-doc
rubygem-abrt
rubygem-io-console
rubygem-mysql2
rubygem-mysql2-doc
rubygem-yard
rubygem-pry
rubygem-power_assert
rubygem-did_you_mean
rubygem-pg-doc
rubygem-pg
rubygem-irb
rubygem-bigdecimal
rubygem-json
rubygem-openssl
rubygem-bundler
libruby2.3 (Ubuntu package)
ruby2.3 (Ubuntu package)
ruby2.5 (Ubuntu package)
libruby2.5 (Ubuntu package)
ruby-debuginfo
ruby-irb
ruby-help
ruby-debugsource
ruby-devel
ruby
ruby2.5-devel-extra
libruby2_5-2_5-debuginfo
ruby2.5
ruby2.5-debuginfo
ruby2.5-debugsource
libruby2_5-2_5
ruby2.5-stdlib
ruby2.5-stdlib-debuginfo
ruby2.5-devel
rh-ruby26-ruby (Red Hat package)
libruby2.7 (Ubuntu package)
ruby2.7 (Ubuntu package)
rh-ruby27-ruby (Red Hat package)
ruby-doc
ruby-default-gems
ruby-libs
rubygems
rubygems-devel
rubygem-mongo
rubygem-mongo-doc
rubygem-psych
rubygem-test-unit
rubygem-bson-doc
rubygem-bson
rubygem-minitest
rubygem-rdoc
rubygem-railties
rubygem-rake
Netcool Operations Insight

How to mitigate CVE-2021-28965

Install updates from vendor's website.

Ruby - addressed in versions 2.5.9, 2.7.3
REXML - update to 3.2.5
cflinuxfs3 - update to 0.236.0
ruby2.5 (Debian package) - update to 2.5.5-3+deb10u4
ruby (Alpine package) - update to 2.7.3-r0
rh-ruby25-ruby (Red Hat package) - update to 2.5.9-9.el7
IBM Cloud Foundry Migration Runtime - update to 4.1.2
Gitlab Community Edition - addressed in versions 13.8.8, 13.9.6, 13.10.3
GitLab Enterprise Edition - addressed in versions 13.8.8, 13.9.6, 13.10.3
rubygem-net-telnet - update to 0.1.1-113
rubygem-net-telnet - update to 0.2.0-136
rubygem-xmlrpc - update to 0.3.0-113
rubygem-xmlrpc - update to 0.3.0-136
rubygem-abrt-doc - update to 0.4.0-1
rubygem-abrt - update to 0.4.0-1
rubygem-io-console - update to 0.4.6-113
rubygem-mysql2 - update to 0.5.3-1
rubygem-mysql2-doc - update to 0.5.3-1
rubygem-io-console - update to 0.5.6-136
rubygem-yard - update to 0.9.26-3.fc34
rubygem-pry - update to 0.13.1-5.fc34
rubygem-power_assert - update to 1.1.1-113
rubygem-power_assert - update to 1.1.7-136
rubygem-did_you_mean - update to 1.2.0-113
rubygem-pg-doc - update to 1.2.3-1.0.1
rubygem-pg - update to 1.2.3-1.0.1
rubygem-irb - update to 1.2.6-136
rubygem-bigdecimal - update to 1.3.4-113
Netcool Operations Insight - update to 1.6.10
rubygem-bigdecimal - update to 2.0.0-136
rubygem-json - update to 2.1.0-113
rubygem-openssl - update to 2.1.2-113
rubygem-openssl - update to 2.1.2-136
rubygem-bundler - update to 2.1.4-136
rubygem-json - update to 2.3.0-136
libruby2.3 (Ubuntu package) - update to 2.3.1-2~ubuntu16.04.16
ruby2.3 (Ubuntu package) - update to 2.3.1-2~ubuntu16.04.16
ruby2.5 (Ubuntu package) - update to 2.5.1-1ubuntu1.9
libruby2.5 (Ubuntu package) - update to 2.5.1-1ubuntu1.9
ruby-debuginfo - update to 2.5.8-113
ruby-irb - update to 2.5.8-113
ruby-help - update to 2.5.8-113
ruby-debugsource - update to 2.5.8-113
ruby-devel - update to 2.5.8-113
ruby - update to 2.5.8-113
ruby2.5-devel-extra - update to 2.5.9-4.17.1
libruby2_5-2_5-debuginfo - update to 2.5.9-4.17.1
ruby2.5 - update to 2.5.9-4.17.1
ruby2.5-debuginfo - update to 2.5.9-4.17.1
ruby2.5-debugsource - update to 2.5.9-4.17.1
libruby2_5-2_5 - update to 2.5.9-4.17.1
ruby2.5-stdlib - update to 2.5.9-4.17.1
ruby2.5-stdlib-debuginfo - update to 2.5.9-4.17.1
ruby2.5-devel - update to 2.5.9-4.17.1
rh-ruby26-ruby (Red Hat package) - update to 2.6.7-119.el7
libruby2.7 (Ubuntu package) - addressed in versions 2.7.0-5ubuntu1.4, 2.7.1-3ubuntu1.3, 2.7.2-4ubuntu1.1
ruby2.7 (Ubuntu package) - addressed in versions 2.7.0-5ubuntu1.4, 2.7.1-3ubuntu1.3, 2.7.2-4ubuntu1.1
rh-ruby27-ruby (Red Hat package) - update to 2.7.3-129.el7
ruby-doc - update to 2.7.3-136
ruby-default-gems - update to 2.7.3-136
ruby-libs - update to 2.7.3-136
ruby-devel - update to 2.7.3-136
ruby - update to 2.7.3-136
ruby - addressed in versions 2.7.3-136.fc32, 2.7.3-136.fc33, 2.7-3320210609104615.601d93de, 2.7-3420210609104615.058368ca, 3.0.1-148.fc34
rubygems - update to 2.7.6-113
rubygems-devel - update to 2.7.6-113
rubygem-mongo - update to 2.11.3-1
rubygem-mongo-doc - update to 2.11.3-1
rubygem-psych - update to 3.0.2-113
rubygem-psych - update to 3.1.0-136
rubygems - update to 3.1.6-136
rubygems-devel - update to 3.1.6-136
rubygem-test-unit - update to 3.2.7-113
rubygem-test-unit - update to 3.3.4-136
rubygem-bson-doc - update to 4.8.1-1
rubygem-bson - update to 4.8.1-1
rubygem-minitest - update to 5.10.3-113
rubygem-minitest - update to 5.13.0-136
rubygem-rdoc - update to 6.0.1.1-113
rubygem-railties - update to 6.1.2.1-2.fc34
rubygem-rdoc - update to 6.2.1-136
rubygem-rake - update to 12.3.0-113
rubygem-rake - update to 13.0.1-136

External References

Related Security Bulletins