Логотип exploitDog
bind: "CVE-2020-26247"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2020-26247"

Количество 9

Количество 9

ubuntu логотип

CVE-2020-26247

около 5 лет назад

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.

CVSS3: 2.6
EPSS: Низкий
redhat логотип

CVE-2020-26247

около 5 лет назад

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-26247

около 5 лет назад

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2020-26247

около 5 лет назад

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers wit ...

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-vr8q-g5c7-m54m

около 5 лет назад

Nokogiri::XML::Schema trusts input by default, exposing risk of XXE vulnerability

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2021-01008

около 5 лет назад

Уязвимость программной библиотеки Nokogiri, связанная с неверным ограничением XML-ссылок на внешние объекты, позволяющая нарушителю провести SSRF-атаку или XXE-атаку

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0237-1

почти 5 лет назад

Security update for rubygem-nokogiri

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0251-1

почти 5 лет назад

Security update for rubygem-nokogiri

EPSS: Низкий
redos логотип

ROS-20250825-02

5 месяцев назад

Множественные уязвимости rubygem-nokogiri

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-26247

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.

CVSS3: 2.6
1%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-26247

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.

CVSS3: 4.3
1%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-26247

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.

CVSS3: 2.6
1%
Низкий
около 5 лет назад
debian логотип
CVE-2020-26247

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers wit ...

CVSS3: 2.6
1%
Низкий
около 5 лет назад
github логотип
GHSA-vr8q-g5c7-m54m

Nokogiri::XML::Schema trusts input by default, exposing risk of XXE vulnerability

CVSS3: 4.3
1%
Низкий
около 5 лет назад
fstec логотип
BDU:2021-01008

Уязвимость программной библиотеки Nokogiri, связанная с неверным ограничением XML-ссылок на внешние объекты, позволяющая нарушителю провести SSRF-атаку или XXE-атаку

CVSS3: 4.3
1%
Низкий
около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0237-1

Security update for rubygem-nokogiri

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:0251-1

Security update for rubygem-nokogiri

почти 5 лет назад
redos логотип
ROS-20250825-02

Множественные уязвимости rubygem-nokogiri

CVSS3: 8.2
5 месяцев назад

Уязвимостей на страницу