Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Translate CVE-2024-43398 (zh_cn) #3351

Merged
merged 2 commits into from
Sep 18, 2024
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 31 additions & 0 deletions zh_cn/news/_posts/2024-08-22-dos-rexml-cve-2024-43398.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
---
layout: news_post
title: "CVE-2024-43398: REXML 中的 DoS 漏洞"
author: "kou"
translator: "GAO Jun"
date: 2024-08-22 03:00:00 +0000
tags: security
lang: zh_cn
---

REXML gem 中存在 DoS 漏洞。此漏洞的 CVE 编号为 [CVE-2024-43398](https://www.cve.org/CVERecord?id=CVE-2024-43398)。我们强烈建议您更新 REXML gem。

## 详情

问题触发场景:当解析的 XML 中存在很多深层元素,且这些元素有同名本地属性时。

此问题仅影响树解析 API。如果您使用 `REXML::Document.new` 来解析 XML,就有可能受到影响。

请更新 REXML gem 至 3.3.6 或更高版本。

## 受影响版本

* REXML gem 3.3.5 或更低版本

## 致谢

感谢 [l33thaxor](https://hackerone.com/l33thaxor) 发现此问题。

## 历史

* 最初发布于 2024-08-22 03:00:00 (UTC)