You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CVE-2024-39908 : When it parses an XML that has many specific characters such as <, 0 and %>. REXML gem may take long time. CVE-2024-41123: When parsing an XML document that has many specific characters such as whitespace character, >] and ]>, REXML gem may take long time.
FYI: They may depend on other commits. So it may be difficult to backport only them. Updating to 3.3.2 or 3.3.3 will be safe. (It doesn't introduce unrelated DoS/bug by wrong backport.)
Hi,
On debian security side we need a statement about commit for this two CVEs
What are the commit fixing this ?
Thanks
Bastien
The text was updated successfully, but these errors were encountered: