CVE-2021-28965 is a high-severity vulnerability affecting the REXML gem in Ruby versions prior to 2.6.7, 2.7.3, and 3.0.1, as well as various Fedora and Ruby-related products. It involves improper handling of XML round-trip issues, leading to the production of an incorrect document after parsing and serialization. With a CVSS score of 7.5 (High), this vulnerability is network-exploitable with low attack complexity and can result in high integrity impact, though confidentiality and availability are not affected. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the KEV catalog. Community discussion and media coverage are minimal, with only one mention and one article, primarily from GitLab's security release.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.2.5CPE matchmatch criteria | cpe:2.3:a:ruby-lang:rexml:*:*:*:*:*:ruby:*:* | ||
< 2.6.7CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* | ||
>= 2.7.0, < 2.7.3CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.0.1CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2021-28965
Mar 14, 2023REXML round-trip instability
Apr 30, 2021The REXML gem before 3.2.5 in Ruby before 2.6.7 2.7.x before 2.7.3 and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing.
Apr 13, 2021ruby: XML round-trip vulnerability in REXML
Apr 5, 2021