Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:15901
HistoryMay 02, 2019 - 5:05 a.m.

XML Entity Expansion (XEE)

2019-05-0205:05:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.13 Low

EPSS

Percentile

95.6%

ruby is vulnerable to XML entity expansion (XEE). A remote attacker is able to crash the process using a malicious XML document that would could cause REXML to use an excessive amount of CPU and memory.

References