CVE-2021-28965

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/04/2021
Last modified:
07/11/2023

Description

The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ruby-lang:rexml:*:*:*:*:*:ruby:*:* 3.2.5 (excluding)
cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* 2.6.7 (excluding)
cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* 2.7.0 (including) 2.7.3 (excluding)
cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* 3.0.0 (including) 3.0.1 (excluding)
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*