CVE-2024-43398 | rexml Gem up to 3.3.5 on Ruby API Parser REXML::Document.new xml entity expansion
A vulnerability classified as problematic has been found in rexml Gem up to 3.3.5 on Ruby. This affects the function REXML::Document.new of the component API Parser. The manipulation leads to xml entity expansion.
This vulnerability is uniquely identified as CVE-2024-43398. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.