Skip to main content

Threats Tagged 'cve-2024-35176'

View all threats tagged with 'cve-2024-35176'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2024-35176

Threats Tagged 'cve-2024-35176'

Click on any threat for detailed analysis and mitigation recommendations

0

A low severity vulnerability (CVE-2024-35176) affects the pcs packages used for command-line configuration of Pacemaker and Corosync utilities in Red Hat Enterprise Linux 8. The issue involves a denial of service (DoS) caused by the REXML parser when processing XML attributes containing many '<' characters. Red Hat has released an update to address this vulnerability in multiple Red Hat Enterprise Linux 8 variants, including High Availability and Resilient Storage editions across various architectures. No known exploits are reported in the wild. The update is available and should be applied to affected systems.

Join the discussion

REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `<`s in an attribute value. Those who need to parse untrusted XMLs may be impacted to this vulnerability. The REXML gem 3.2.7 or later include the patch to fix this vulnerability. As a workaround, don't parse untrusted XMLs.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cve-2024-35176
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses