Lucene search

K
osvGoogleOSV:GHSA-J96R-XVJQ-R9PG
HistoryOct 24, 2017 - 6:33 p.m.

activesupport vulnerable to Denial of Service via large XML document depth

2017-10-2418:33:36
Google
osv.dev
14

EPSS

0.016

Percentile

87.3%

The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.