CVE-2021-28965
Published: 12 April 2021
The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing.
Priority
Status
Package | Release | Status |
---|---|---|
ruby-rexml
Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
focal |
Does not exist
|
|
groovy |
Ignored
(end of life)
|
|
hirsute |
Ignored
(end of life)
|
|
impish |
Ignored
(end of life)
|
|
jammy |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Released
(3.2.5)
|
|
xenial |
Does not exist
|
|
Patches:
upstream: https://github.com/ruby/rexml/commit/a659c63e37414506dfb0d4655e031bb7a2e73fc8 upstream: https://github.com/ruby/rexml/commit/2fe62e29094d95921d7e19abbd2e26b23d78dc5b upstream: https://github.com/ruby/rexml/commit/6a250d2cd1194c2be72becbdd9c3e770aa16e752 upstream: https://github.com/ruby/rexml/commit/f7bab8937513b1403cea5aff874cbf32fd5e8551 upstream: https://github.com/ruby/rexml/commit/f9d88e4948b4a43294c25dc0edb16815bd9d8618 upstream: https://github.com/ruby/rexml/commit/9b311e59ae05749e082eb6bbefa1cb620d1a786e upstream: https://github.com/ruby/rexml/commit/3c137eb119550874b2b3e27d12b733ca67033377 |
||
ruby2.3
Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Released
(2.3.1-2~ubuntu16.04.16)
|
|
ruby2.5
Launchpad, Ubuntu, Debian |
bionic |
Released
(2.5.1-1ubuntu1.9)
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Released
(2.5.9)
|
|
xenial |
Does not exist
|
|
Patches:
upstream: https://github.com/ruby/ruby/commit/48706204503ee83a9925f2a482bcf37ddcc7fa48 |
||
ruby2.7
Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
focal |
Released
(2.7.0-5ubuntu1.4)
|
|
groovy |
Released
(2.7.1-3ubuntu1.3)
|
|
hirsute |
Released
(2.7.2-4ubuntu1.1)
|
|
impish |
Released
(2.7.3-2ubuntu1)
|
|
trusty |
Does not exist
|
|
upstream |
Released
(2.7.3)
|
|
xenial |
Does not exist
|
|
Patches:
upstream: https://github.com/ruby/ruby/commit/b59e5a64be40b93370afbb0accfcb73c4d682045 |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.5 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | High |
Availability impact | None |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |