CVE Vulnerabilities

CVE-2014-8090

Published: Nov 21, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.

Affected Software

NameVendorStart VersionEnd Version
RubyRuby-lang*1.9.3 (including)
RubyRuby-lang1.9.3 (including)1.9.3 (including)
RubyRuby-lang1.9.3-p0 (including)1.9.3-p0 (including)
RubyRuby-lang1.9.3-p125 (including)1.9.3-p125 (including)
RubyRuby-lang1.9.3-p194 (including)1.9.3-p194 (including)
RubyRuby-lang1.9.3-p286 (including)1.9.3-p286 (including)
RubyRuby-lang1.9.3-p383 (including)1.9.3-p383 (including)
RubyRuby-lang1.9.3-p385 (including)1.9.3-p385 (including)
RubyRuby-lang1.9.3-p392 (including)1.9.3-p392 (including)
RubyRuby-lang1.9.3-p426 (including)1.9.3-p426 (including)
RubyRuby-lang1.9.3-p429 (including)1.9.3-p429 (including)
RubyRuby-lang1.9.3-p448 (including)1.9.3-p448 (including)
RubyRuby-lang1.9.3-p545 (including)1.9.3-p545 (including)
RubyRuby-lang1.9.3-p547 (including)1.9.3-p547 (including)
RubyRuby-lang2.0.0 (including)2.0.0 (including)
RubyRuby-lang2.0.0-p0 (including)2.0.0-p0 (including)
RubyRuby-lang2.0.0-p195 (including)2.0.0-p195 (including)
RubyRuby-lang2.0.0-p247 (including)2.0.0-p247 (including)
RubyRuby-lang2.0.0-p451 (including)2.0.0-p451 (including)
RubyRuby-lang2.0.0-p481 (including)2.0.0-p481 (including)
RubyRuby-lang2.0.0-p576 (including)2.0.0-p576 (including)
RubyRuby-lang2.0.0-p594 (including)2.0.0-p594 (including)
RubyRuby-lang2.1.1 (including)2.1.1 (including)
RubyRuby-lang2.1.2 (including)2.1.2 (including)
RubyRuby-lang2.1.3 (including)2.1.3 (including)
RubyRuby-lang2.1.4 (including)2.1.4 (including)
Red Hat Enterprise Linux 6RedHatruby-0:1.8.7.374-3.el6_6*
Red Hat Enterprise Linux 7RedHatruby-0:2.0.0.353-22.el7_0*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6RedHatruby193-ruby-0:1.9.3.484-50.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6RedHatruby200-ruby-0:2.0.0.353-24.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUSRedHatruby193-ruby-0:1.9.3.484-50.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUSRedHatruby200-ruby-0:2.0.0.353-24.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUSRedHatruby193-ruby-0:1.9.3.484-50.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUSRedHatruby200-ruby-0:2.0.0.353-24.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.6 EUSRedHatruby193-ruby-0:1.9.3.484-50.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.6 EUSRedHatruby200-ruby-0:2.0.0.353-24.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7RedHatruby193-ruby-0:1.9.3.484-50.el7*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7RedHatruby200-ruby-0:2.0.0.353-24.el7*
Ruby1.8Ubuntulucid*
Ruby1.8Ubuntuprecise*
Ruby1.9.1Ubuntulucid*
Ruby1.9.1Ubuntuprecise*
Ruby1.9.1Ubuntutrusty*
Ruby1.9.1Ubuntuutopic*
Ruby1.9.1Ubuntuvivid*
Ruby2.0Ubuntutrusty*
Ruby2.0Ubuntuutopic*
Ruby2.1Ubuntudevel*
Ruby2.1Ubuntuutopic*
Ruby2.1Ubuntuvivid*
Ruby2.1Ubuntuwily*

References