ruby-lang.orgãããREXMLã®èå¼±æ§ã«é¢ããå ±åãããã¾ããã REXMLã®DoSèå¼±æ§ Railsã§XMLãªã¯ã¨ã¹ãã®ãã¼ã¹ã«ä½¿ç¨ããã¦ããREXMLã«ãDoSèå¼±æ§ãçºè¦ããã¾ãããXML entity explosion attackã¨å¼ã°ããæ»æææ³ã«ãããã¦ã¼ã¶ããä¸ããããXMLã解æãããããªã¢ããªã±ã¼ã·ã§ã³ããµã¼ãã¹ä¸è½(DoS)ç¶æ ã«ãããã¨ãã§ãã¾ãã大é¨åã®Railsã¢ããªã±ã¼ã·ã§ã³ã¯ãã®æ»æã«å¯¾ãã¦èå¼±ã§ãã åé¡ã«å¯¾å¦ããããã®Gemããªãªã¼ã¹ããã¦ãããããªã®ã§ã 以ä¸ã®ããã«å¯¾å¦ãã¾ããã Gemãã¤ã³ã¹ãã¼ã«
{{#tags}}- {{label}}
{{/tags}}