Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qxcg-xjjg-66mj

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Nokogiri vulnerable to libxslt protection mechanism bypass

A dependency of Nokogiri, libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

Ссылки

Пакеты

Наименование

nokogiri

rubygems
Затронутые версииВерсия исправления

< 1.10.3

1.10.3

EPSS

Процентиль: 75%
0.00934
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

CVSS3: 6.3
redhat
больше 6 лет назад

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

CVSS3: 9.8
nvd
больше 6 лет назад

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

CVSS3: 9.8
debian
больше 6 лет назад

libxslt through 1.1.33 allows bypass of a protection mechanism because ...

suse-cvrf
около 6 лет назад

Security update for libxslt

EPSS

Процентиль: 75%
0.00934
Низкий

9.8 Critical

CVSS3