CVE-2020-26247
Summary
| CVE | CVE-2020-26247 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-30 19:15:00 UTC |
| Updated | 2022-10-19 18:53:00 UTC |
| Description | Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Nokogiri::XML::Schema trusts input by default, exposing risk of an XXE vulnerability · Advisory · sparklemotion/nokogiri · GitHub |
CONFIRM |
github.com |
Mitigation, Third Party Advisory |
| [SECURITY] [DLA 2678-1] ruby-nokogiri security update |
MLIST |
lists.debian.org |
|
| Nokogiri: Multiple Vulnerabilities (GLSA 202208-29) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] [DLA 3149-1] ruby-nokogiri security update |
MLIST |
lists.debian.org |
|
| nokogiri | RubyGems.org | your community gem host |
MISC |
rubygems.org |
Product, Third Party Advisory |
| HackerOne |
MISC |
hackerone.com |
Permissions Required |
| Release v1.11.0.rc4 / 2020-12-29 · sparklemotion/nokogiri · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| feat: XML::Schema and RelaxNG creation accept optional ParseOptions · sparklemotion/nokogiri@9c87439 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178661 Debian Security Update for ruby-nokogiri (DLA 2678-1)
- 181134 Debian Security Update for ruby-nokogiri (DLA 3149-1)
- 239895 Red Hat Update for Satellite 6.10 (RHSA-2021:4702)
- 501920 Alpine Linux Security Update for ruby-nokogiri
- 690369 Free Berkeley Software Distribution (FreeBSD) Security Update for nokogiri (13c54e6d-5c45-11eb-b4e2-001b217b3468)
- 710597 Gentoo Linux Nokogiri Multiple Vulnerabilities (GLSA 202208-29)
- 750375 OpenSUSE Security Update for rubygem-nokogiri (openSUSE-SU-2021:0237-1)