Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2678-1 | ruby-nokogiri security update |
Debian DLA |
DLA-3149-1 | ruby-nokogiri security update |
EUVD |
EUVD-2020-1507 | Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4. |
Github GHSA |
GHSA-vr8q-g5c7-m54m | Nokogiri::XML::Schema trusts input by default, exposing risk of XXE vulnerability |
Ubuntu USN |
USN-7659-1 | Nokogiri vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T15:56:04.939Z
Reserved: 2020-10-01T00:00:00
Link: CVE-2020-26247
No data.
Status : Modified
Published: 2020-12-30T19:15:12.920
Modified: 2024-11-21T05:19:38.553
Link: CVE-2020-26247
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN