Lucene search

K
osvGoogleOSV:USN-4922-1
HistoryApr 20, 2021 - 5:01 p.m.

ruby2.3, ruby2.5, ruby2.7 vulnerability

2021-04-2017:01:53
Google
osv.dev
8

7.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.1%

Juho Nurminen discovered that the REXML gem bundled with Ruby incorrectly
parsed and serialized XML documents. A remote attacker could possibly use
this issue to perform an XML round-trip attack.