Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-26247

Опубликовано: 30 дек. 2020
Источник: redhat
CVSS3: 4.3

Описание

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.

A flaw was found in Nokogiri. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XML External Entity (XXE) or Server-side request forgery (SSRF) attacks. The highest threat from this vulnerability is to data confidentiality.

Меры по смягчению последствий

There are no known workarounds for affected versions. Please refer to the upstream advisory page for additional information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5rubygem-nokogiriWill not fix
Red Hat Satellite 6tfm-ror52-rubygem-nokogiriWill not fix
3scale API Management 2.11 on RHEL 73scale-amp2/3scale-rhel7-operatorFixedRHSA-2021:519116.12.2021
3scale API Management 2.11 on RHEL 73scale-amp2/3scale-rhel7-operator-metadataFixedRHSA-2021:519116.12.2021
3scale API Management 2.11 on RHEL 73scale-amp2/apicast-rhel7-operatorFixedRHSA-2021:519116.12.2021
3scale API Management 2.11 on RHEL 73scale-amp2/apicast-rhel7-operator-metadataFixedRHSA-2021:519116.12.2021
3scale API Management 2.11 on RHEL 73scale-amp2/memcached-rhel7FixedRHSA-2021:519116.12.2021
3scale API Management 2.11 on RHEL 73scale-amp2/system-rhel7FixedRHSA-2021:519116.12.2021
3scale API Management 2.11 on RHEL 83scale-amp2/apicast-gateway-rhel8FixedRHSA-2021:519116.12.2021
3scale API Management 2.11 on RHEL 83scale-amp2/backend-rhel8FixedRHSA-2021:519116.12.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1912487rubygem-nokogiri: XML external entity injection via Nokogiri::XML::Schema

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 2.6
ubuntu
около 5 лет назад

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.

CVSS3: 2.6
nvd
около 5 лет назад

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.

CVSS3: 2.6
debian
около 5 лет назад

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers wit ...

CVSS3: 4.3
github
около 5 лет назад

Nokogiri::XML::Schema trusts input by default, exposing risk of XXE vulnerability

CVSS3: 4.3
fstec
около 5 лет назад

Уязвимость программной библиотеки Nokogiri, связанная с неверным ограничением XML-ссылок на внешние объекты, позволяющая нарушителю провести SSRF-атаку или XXE-атаку

4.3 Medium

CVSS3