CVE-2014-8090
Estado: ModificadaMedia (5)—
The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 5.60%
- Percentil entre todas las CVEs puntuadas: 93
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://advisories.mageia.org/MGASA-2014-0472.html
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html
- http://lists.opensuse.org/opensuse-updates/2014-12/msg00035.html
- http://lists.opensuse.org/opensuse-updates/2015-01/msg00000.html
- http://lists.opensuse.org/opensuse-updates/2015-01/msg00004.html
- http://rhn.redhat.com/errata/RHSA-2014-1911.html
- http://rhn.redhat.com/errata/RHSA-2014-1912.html
- http://rhn.redhat.com/errata/RHSA-2014-1913.html
- http://rhn.redhat.com/errata/RHSA-2014-1914.html
- http://secunia.com/advisories/59948
- http://secunia.com/advisories/62050
- http://secunia.com/advisories/62748
- http://www.debian.org/security/2015/dsa-3157
- http://www.debian.org/security/2015/dsa-3159
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:129
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.securityfocus.com/bid/71230
- http://www.ubuntu.com/usn/USN-2412-1
- https://support.apple.com/HT205267
- https://www.ruby-lang.org/en/news/2014/11/13/rexml-dos-cve-2014-8090/
- http://advisories.mageia.org/MGASA-2014-0472.html
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html
- http://lists.opensuse.org/opensuse-updates/2014-12/msg00035.html
- http://lists.opensuse.org/opensuse-updates/2015-01/msg00000.html
- http://lists.opensuse.org/opensuse-updates/2015-01/msg00004.html
- http://rhn.redhat.com/errata/RHSA-2014-1911.html
- http://rhn.redhat.com/errata/RHSA-2014-1912.html
- http://rhn.redhat.com/errata/RHSA-2014-1913.html
- http://rhn.redhat.com/errata/RHSA-2014-1914.html
- http://secunia.com/advisories/59948
- http://secunia.com/advisories/62050
- http://secunia.com/advisories/62748
- http://www.debian.org/security/2015/dsa-3157
- http://www.debian.org/security/2015/dsa-3159
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:129
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.securityfocus.com/bid/71230
- http://www.ubuntu.com/usn/USN-2412-1
- https://support.apple.com/HT205267
- https://www.ruby-lang.org/en/news/2014/11/13/rexml-dos-cve-2014-8090/
JSON original (NVD)
Mostrar
{
"id": "CVE-2014-8090",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-11-21T15:59:04.243",
"references": [
{
"url": "http://advisories.mageia.org/MGASA-2014-0472.html",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2014-12/msg00035.html",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2015-01/msg00000.html",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2015-01/msg00004.html",
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-1911.html",
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-1912.html",
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-1913.html",
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-1914.html",
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/59948",
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/62050",
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/62748",
"source": "secalert@redhat.com"
},
{
"url": "http://www.debian.org/security/2015/dsa-3157",
"source": "secalert@redhat.com"
},
{
"url": "http://www.debian.org/security/2015/dsa-3159",
"source": "secalert@redhat.com"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:129",
"source": "secalert@redhat.com"
},
{
"url": "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/71230",
"source": "secalert@redhat.com"
},
{
"url": "http://www.ubuntu.com/usn/USN-2412-1",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://support.apple.com/HT205267",
"source": "secalert@redhat.com"
},
{
"url": "https://www.ruby-lang.org/en/news/2014/11/13/rexml-dos-cve-2014-8090/",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://advisories.mageia.org/MGASA-2014-0472.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2014-12/msg00035.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2015-01/msg00000.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2015-01/msg00004.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-1911.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-1912.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-1913.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-1914.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/59948",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/62050",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/62748",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2015/dsa-3157",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2015/dsa-3159",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:129",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/71230",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/USN-2412-1",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/HT205267",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.ruby-lang.org/en/news/2014/11/13/rexml-dos-cve-2014-8090/",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080."
},
{
"lang": "es",
"value": "El analizador REXML en Ruby 1.9.x anterior a 1.9.3 patchlevel 551, 2.0.x anterior a 2.0.0 patchlevel 598, y 2.1.x anterior a 2.1.5 permite a atacantes remotos causar una denegación de servicio (consumo de CPU y memoria) a través de un documento XML manipulado que contiene una cadena vacía en una entidad que se utiliza en un número grande de referencias de entidad anidadas, también conocido como un ataque de expansión de entidad XML (XEE). NOTA: esta vulnerabilidad existe debido a una solución incompleta para CVE-2013-1821 y CVE-2014-8080."
}
],
"lastModified": "2026-06-17T00:16:13.157",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:*:p550:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1C6F683D-B441-4778-B02E-F9A33ADD6597",
"versionEndIncluding": "1.9.3"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0535DC9-EB0E-4745-80AC-4A020DF26E38"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.3:p0:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "94F5AA37-B466-4E2E-B217-5119BADDD87B"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.3:p125:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6DF0F0F5-4022-4837-9B40-4B1127732CC9"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.3:p194:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B3848B08-85C2-4AAD-AA33-CCEB80EF5B32"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.3:p286:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B7927D40-2A3A-43AD-99F6-CE61882A1FF4"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.3:p383:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AA406EC6-6CA5-40A6-A879-AA8940CBEF07"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.3:p385:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D041884-3921-4466-9A48-F644FDDA9D50"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.3:p392:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "397A2EA7-6F83-427B-8578-3794EBF04849"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.3:p426:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "298A5681-F756-4952-A9F8-E4C76736DF8F"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.3:p429:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BC5A12F7-47E2-4AC7-A41B-F4B01319002D"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.3:p448:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B56582F2-0D51-4FAD-888F-3342B229A557"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.3:p545:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F3ADD67F-D944-461F-94DA-E00D3556416F"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.3:p547:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "93AA1766-1936-4704-A3D0-D4F280373D1C"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:2.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B03B7561-A854-4EFA-9E4E-CFC4EEAE4EE1"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:2.0.0:p0:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D2423B85-0971-42AC-8B64-819008BC5778"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:2.0.0:p195:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1C663278-3B2A-4B7C-959A-2AA804467F21"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:2.0.0:p247:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B7927149-A76A-48BC-8405-7375FC7D7486"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:2.0.0:p451:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "46485519-C2FB-4767-B699-9F51FDCF29E5"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:2.0.0:p481:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "19CF27FB-DCF5-4533-B309-55615AE21A63"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:2.0.0:p576:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B9865DD1-F2AF-40B6-848A-EA9FD37034DD"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:2.0.0:p594:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C10BD21E-B9FA-4B57-B617-0108A00D6132"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:2.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8DF046E4-503B-4A10-BEAB-3144BD86EA49"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:2.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9FCA45F1-3038-413A-B8C3-EE366A4E6248"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:2.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF6AF5E3-4EB8-48A3-B8E9-C79C08C38994"
},
{
"criteria": "cpe:2.3:a:ruby-lang:ruby:2.1.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6AE2B154-8126-4A38-BAB6-915207764FC0"
}
],
"operator": "OR"
}
]
}
],
"evaluatorComment": "<a href=\"http://cwe.mitre.org/data/definitions/611.html\" target=\"_blank\">CWE-611: Improper Restriction of XML External Entity Reference ('XXE')</a>",
"sourceIdentifier": "secalert@redhat.com"
}