HIGH 7.5 RubyGems

REXML round-trip instability

GHSA-8cr8-4vfw-mr7h · BIT-ruby-2021-28965 · BIT-ruby-min-2021-28965 · CVE-2021-28965

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing.

Ready to move

Start Securing

Free, no credit card | First findings in minutes