Input validation error in REXML - CVE-2024-35176
Published: July 16, 2024 / Updated: December 27, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when parsing XML that has multiple bracket character occurrences (e.g. "<") in an attribute value. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Basesystem Module
Ubuntu
openEuler
Fedora
Software Support app (Android)
APEX Cloud Platform for Microsoft Azure
Software Support App (iOS)
Cognos Analytics Mobile (Android)
Cognos Analytics Mobile (iOS)
Dell EMC VxRail Appliance
rubygem-net-telnet
rubygem-rss
rubygem-abrt-doc
rubygem-abrt
rubygem-xmlrpc
rubygem-io-console
rubygem-mysql2
rubygem-mysql2-doc
rubygem-typeprof
rubygem-pg-doc
rubygem-pg
rubygem-power_assert
rubygem-did_you_mean
rubygem-bigdecimal
rubygem-rbs
rubygem-bundler-doc
rubygem-bundler
rubygem-json
rubygem-openssl
ruby2.3 (Ubuntu package)
ruby2.5 (Ubuntu package)
rubygem-mongo-doc
rubygem-mongo
ruby-irb
ruby-doc
ruby
ruby-devel
ruby-libs
ruby2.5-debuginfo
ruby2.5-devel
ruby2.5-devel-extra
ruby2.5-debugsource
ruby2.5-stdlib
ruby2.5
libruby2_5-2_5-debuginfo
ruby2.5-stdlib-debuginfo
libruby2_5-2_5
ruby2.7 (Ubuntu package)
libruby2.7 (Ubuntu package)
rubygems-devel
rubygems
rubygem-psych
ruby-debuginfo
ruby-debugsource
ruby-help
ruby3.2 (Ubuntu package)
libruby3.2 (Ubuntu package)
rubygem-rexml
rubygem-test-unit
libruby3.3 (Ubuntu package)
ruby3.3 (Ubuntu package)
dev-ruby/rexml
rubygem-bson
rubygem-bson-doc
rubygem-minitest
rubygem-rdoc
rubygem-rake
ruby3.0 (Ubuntu package)
libruby3.0 (Ubuntu package)
APEX Cloud Platform for Red Hat OpenShift
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
IBM License Metric Tool
How to mitigate CVE-2024-35176
Software Support app (Android) - update to 2.0.0
APEX Cloud Platform for Microsoft Azure - update to 01.04.00.00
Software Support App (iOS) - update to 2.0.0
Dell EMC VxRail Appliance - addressed in versions 7.0.533, 8.320
rubygem-net-telnet - update to 0.1.1-112.0.1
rubygem-rss - update to 0.2.9-136
rubygem-abrt-doc - update to 0.3.0-4
rubygem-abrt - update to 0.3.0-4
rubygem-xmlrpc - update to 0.3.0-112.0.1
rubygem-io-console - update to 0.4.6-112.0.1
rubygem-mysql2 - update to 0.4.10-4
rubygem-mysql2-doc - update to 0.4.10-4
rubygem-io-console - update to 0.5.7-136
rubygem-typeprof - update to 0.15.2-136
rubygem-pg-doc - update to 1.0.0-3.0.1
rubygem-pg - update to 1.0.0-3.0.1
rubygem-power_assert - update to 1.1.1-112.0.1
Cognos Analytics Mobile (Android) - update to 1.1.20
Cognos Analytics Mobile (iOS) - update to 1.1.20
rubygem-did_you_mean - update to 1.2.0-112.0.1
rubygem-bigdecimal - update to 1.3.4-112.0.1
rubygem-rbs - update to 1.4.0-136
rubygem-did_you_mean - update to 1.5.0-136
rubygem-bundler-doc - update to 1.16.1-4
rubygem-bundler - update to 1.16.1-4
rubygem-json - update to 2.1.0-112.0.1
rubygem-openssl - update to 2.1.2-112.0.1
rubygem-openssl - update to 2.2.1-136
rubygem-bundler - update to 2.2.32-136
ruby2.3 (Ubuntu package) - addressed in versions 2.3.1-2~ubuntu16.04.16+esm11, 2.5.1-1ubuntu1.16+esm6, 2.7.0-5ubuntu1.18+esm3
ruby2.5 (Ubuntu package) - addressed in versions 2.5.1-1ubuntu1.16+esm5, 2.7.0-5ubuntu1.18+esm1, 3.0.2-7ubuntu2.11, 3.2.3-1ubuntu0.24.04.6, 3.3.7-1ubuntu2.1
rubygem-mongo-doc - update to 2.5.1-2
rubygem-mongo - update to 2.5.1-2
rubygem-json - update to 2.5.1-136
ruby-irb - update to 2.5.9-112.0.1
ruby-doc - update to 2.5.9-112.0.1
ruby - update to 2.5.9-112.0.1
ruby-devel - update to 2.5.9-112.0.1
ruby-libs - update to 2.5.9-112.0.1
ruby2.5-debuginfo - update to 2.5.9-150000.4.32.1
ruby2.5-devel - update to 2.5.9-150000.4.32.1
ruby2.5-devel-extra - update to 2.5.9-150000.4.32.1
ruby2.5-debugsource - update to 2.5.9-150000.4.32.1
ruby2.5-stdlib - update to 2.5.9-150000.4.32.1
ruby2.5 - update to 2.5.9-150000.4.32.1
libruby2_5-2_5-debuginfo - update to 2.5.9-150000.4.32.1
ruby2.5-stdlib-debuginfo - update to 2.5.9-150000.4.32.1
libruby2_5-2_5 - update to 2.5.9-150000.4.32.1
ruby2.7 (Ubuntu package) - update to 2.7.0-5ubuntu1.15
libruby2.7 (Ubuntu package) - update to 2.7.0-5ubuntu1.15
rubygems-devel - update to 2.7.6.3-112.0.1
rubygems - update to 2.7.6.3-112.0.1
rubygem-bigdecimal - update to 3.0.0-136
ruby3.0 (Ubuntu package) - update to 3.0.2-7ubuntu2.8
libruby3.0 (Ubuntu package) - update to 3.0.2-7ubuntu2.8
rubygem-psych - update to 3.0.2-112.0.1
ruby - update to 3.0.3-136
ruby-debuginfo - update to 3.0.3-136
ruby-debugsource - update to 3.0.3-136
ruby-devel - update to 3.0.3-136
ruby-help - update to 3.0.3-136
ruby-irb - update to 3.0.3-136
APEX Cloud Platform for Red Hat OpenShift - update to 03.01.02.00
ruby3.2 (Ubuntu package) - update to 3.2.3-1ubuntu0.24.04.3
libruby3.2 (Ubuntu package) - update to 3.2.3-1ubuntu0.24.04.3
rubygem-rexml - update to 3.2.5-136
ruby - addressed in versions 3.2.5-183.fc39, 3.3.4-11.fc40
rubygem-test-unit - update to 3.2.7-112.0.1
rubygems - update to 3.2.32-136
rubygems-devel - update to 3.2.32-136
rubygem-psych - update to 3.3.2-136
libruby3.3 (Ubuntu package) - update to 3.3.4-2ubuntu5.1
ruby3.3 (Ubuntu package) - update to 3.3.4-2ubuntu5.1
rubygem-test-unit - update to 3.3.7-136
dev-ruby/rexml - update to 3.3.9
rubygem-bson - update to 4.3.0-2
rubygem-bson-doc - update to 4.3.0-2
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.6, 5.0.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0.3
rubygem-minitest - update to 5.10.3-112.0.1
rubygem-minitest - update to 5.14.2-136
rubygem-rdoc - update to 6.0.1.1-112.0.1
rubygem-rdoc - update to 6.3.3-136
IBM License Metric Tool - update to 9.2.36
rubygem-rake - update to 12.3.3-112.0.1
rubygem-rake - update to 13.0.3-136
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Denial of service in REXML gem
- Input validation error in IBM License Metric Tool
- openEuler update for ruby
- Red Hat Enterprise Linux 8 update for ruby module
- Fedora 40 update for ruby
- Input validation error in IBM Watson Discovery for IBM Cloud Pak for Data
- Fedora 39 update for ruby
- IBM Watson Assistant for IBM Cloud Pak for Data update for Ruby REXML
- SUSE update for ruby2.5
- Ubuntu update for ruby3.0
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (Android)
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (iOS)
- Ubuntu update for ruby2.7
- Multiple vulnerabilities in IBM Software Support app
- Anolis OS update for ruby:2.5 module
- Multiple vulnerabilities in Dell VxRail Appliance
- Multiple vulnerabilities in Dell VxRail Appliance 7.x
- APEX Cloud Platform for Microsoft Azure update for third-party components
- Multiple vulnerabilities in Dell APEX Cloud Platform for Red Hat OpenShift
- Gentoo update for REXML
- Ubuntu update for ruby2.5
- Ubuntu update for ruby2.3