Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-26247

Опубликовано: 30 дек. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4
CVSS3: 2.6

Описание

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

1.16.4+dfsg-1build1
esm-apps/bionic

not-affected

code not present
esm-apps/focal

released

1.10.7+dfsg1-2ubuntu0.1~esm2
esm-apps/jammy

not-affected

1.13.1+dfsg-2
esm-apps/noble

not-affected

1.16.2+dfsg-1build1
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present
focal

ignored

end of standard support, was needs-triage
groovy

ignored

end of life

Показывать по

EPSS

Процентиль: 71%
0.00678
Низкий

4 Medium

CVSS2

2.6 Low

CVSS3

Связанные уязвимости

CVSS3: 4.3
redhat
около 5 лет назад

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.

CVSS3: 2.6
nvd
около 5 лет назад

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.

CVSS3: 2.6
debian
около 5 лет назад

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers wit ...

CVSS3: 4.3
github
около 5 лет назад

Nokogiri::XML::Schema trusts input by default, exposing risk of XXE vulnerability

CVSS3: 4.3
fstec
около 5 лет назад

Уязвимость программной библиотеки Nokogiri, связанная с неверным ограничением XML-ссылок на внешние объекты, позволяющая нарушителю провести SSRF-атаку или XXE-атаку

EPSS

Процентиль: 71%
0.00678
Низкий

4 Medium

CVSS2

2.6 Low

CVSS3