CVE-2021-28965

Source
https://cve.org/CVERecord?id=CVE-2021-28965
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-28965.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-28965
Aliases
Downstream
ALPINE (1)
AZL (1)
BELL (1)
CLEANSTART (1)
CLSA (1)
DEBIAN (1)
JLSEC (1)
MGASA (1)
OESA (1)
openSUSE (8)
RHSA (11)
RLSA (3)
SUSE (1)
UBUNTU (1)
Related
Published
2021-04-21T07:15:07Z
Modified
2026-07-07T08:50:50Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing.

Database specific
{
    "unresolved_ranges":  [
        {
            "cpes":  [
                "cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "34"
                },
                {
                    "last_affected":  "34"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "fedoraproject:fedora"
        }
    ]
}
References

Affected packages

Git / github.com/ruby/rexml

Affected ranges

Type
GIT
Repo
https://github.com/ruby/rexml
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:ruby-lang:rexml:*:*:*:*:*:ruby:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "3.2.5"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

v3.*
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.2
v3.2.3
v3.2.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-28965.json"

Git / github.com/ruby/ruby

Affected ranges

Type
GIT
Repo
https://github.com/ruby/ruby
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "2.6.7"
        },
        {
            "introduced":  "2.7.0"
        },
        {
            "fixed":  "2.7.3"
        },
        {
            "introduced":  "3.0.0"
        },
        {
            "fixed":  "3.0.1"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

Other
v1_0_r2
v2_7_0
v2_7_1
v2_7_2
v3_0_0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-28965.json"