VYPR
Unrated severityNVD Advisory· Published Nov 21, 2014· Updated May 6, 2026

CVE-2014-8090

CVE-2014-8090

Description

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.

Affected products

26
  • Ruby Lang/Ruby26 versions
    cpe:2.3:a:ruby-lang:ruby:1.9.3:*:*:*:*:*:*:*+ 25 more
    • cpe:2.3:a:ruby-lang:ruby:1.9.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.3:p0:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.3:p125:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.3:p194:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.3:p286:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.3:p383:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.3:p385:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.3:p392:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.3:p426:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.3:p429:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.3:p448:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.3:p545:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.3:p547:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:2.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:2.0.0:p0:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:2.0.0:p195:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:2.0.0:p247:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:2.0.0:p451:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:2.0.0:p481:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:2.0.0:p576:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:2.0.0:p594:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:2.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:2.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:2.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:2.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:*:p550:*:*:*:*:*:*range: <=1.9.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

20

News mentions

0

No linked articles in our index yet.