CVE-2014-8090

Advisory lineage Upstream: 0 Downstream: 14
Modified
Published: 21 Nov 2014, 15:00
Last modified:06 Aug 2024, 13:10

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
11.9% MEDIUM
12% probability +1.41%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

21 Nov 2014, 15:00
Published
Vulnerability first disclosed
06 Aug 2024, 13:10
Last Modified
Vulnerability information updated

Description

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 11.90% Percentile: 94%

Affected Systems

  • ruby-langruby

    ≤ 1.9.3 | 1.9.3 | 1.9.3:p0 | 1.9.3:p125 | 1.9.3:p194 | 1.9.3:p286 | 1.9.3:p383 | 1.9.3:p385 | 1.9.3:p392 | 1.9.3:p426 | 1.9.3:p429 | 1.9.3:p448 | 1.9.3:p545 | 1.9.3:p547 | 2.0.0 | 2.0.0:p0 | 2.0.0:p195 | 2.0.0:p247 | 2.0.0:p451 | 2.0.0:p481 | 2.0.0:p576 | 2.0.0:p594 | 2.1.1 | 2.1.2 | 2.1.3 | 2.1.4

References (20)