CVE-2012-6685
published 2020-02-19CVE-2012-6685: Nokogiri before 1.5.4 is vulnerable to XXE attacks
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
2.17%
80.2th percentile
Nokogiri before 1.5.4 is vulnerable to XXE attacks
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | apple_tv | — | — |
| debian | ruby-nokogiri | < ruby-nokogiri 1.5.4-1 (bookworm) | ruby-nokogiri 1.5.4-1 (bookworm) |
| nokogiri | nokogiri | < 1.5.4 | 1.5.4 |
| nokogiri | nokogiri | >= 0 < 1.5.4 | 1.5.4 |
| redhat | cloudforms_management_engine | — | — |
| redhat | enterprise_mrg | — | — |
| redhat | openshift | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | satellite | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-nokogiri: XML eXternal Entity (XXE) flaw
vendor_redhat·2012-06-06·CVSS 7.5
CVE-2012-6685 [HIGH] CWE-611 rubygem-nokogiri: XML eXternal Entity (XXE) flaw
rubygem-nokogiri: XML eXternal Entity (XXE) flaw
Nokogiri before 1.5.4 is vulnerable to XXE attacks
Statement: This issue affects the versions of ruby193-rubygem-nokogiri as shipped with Red Hat Satellite 6 and Red Hat OpenStack 6. Red Hat Product Security has rated this issue as having moderate security impact. A future update may address this issue.
Red Hat Product Security has rated this issue as having no security impact for rubygem-nokogiri as shipped with: Red Hat Enterprise MRG 2.5, Red Hat Subscription Asset Manager 1.3, Red Hat CloudForms Management Engine 5.3.0, Red Hat OpenShift Enterprise 2.2.0; for ruby193-rubygem-nokogiri as shipped with Red Hat Satellite 6, Red Hat Subscription Asset Manager 1.3, Red Hat CloudForms Management Engine 5.3.0, Red Hat OpenStack 4.0, Red Hat Op
Debian
CVE-2012-6685: ruby-nokogiri - Nokogiri before 1.5.4 is vulnerable to XXE attacks
vendor_debian·2012·CVSS 7.5
CVE-2012-6685 [HIGH] CVE-2012-6685: ruby-nokogiri - Nokogiri before 1.5.4 is vulnerable to XXE attacks
Nokogiri before 1.5.4 is vulnerable to XXE attacks
Scope: local
bookworm: resolved (fixed in 1.5.4-1)
bullseye: resolved (fixed in 1.5.4-1)
forky: resolved (fixed in 1.5.4-1)
sid: resolved (fixed in 1.5.4-1)
trixie: resolved (fixed in 1.5.4-1)
Apple
CVE-2012-6685: Apple TV 7.2.1
vendor_apple·CVSS 7.5
CVE-2012-6685 [HIGH] CVE-2012-6685: Apple TV 7.2.1
Apple Security Update: About the security content of Apple TV 7.2.1
Product: Apple TV
Version: 7.2.1
CVE: CVE-2012-6685
Component: CVE-ID
Impact: A malicious application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue existed in handling of malformed XPC messages. This issue was improved through improved bounds checking.
OSV
Nokogiri is vulnerable to XML External Entity (XXE) attack
osv·2022-04-23
CVE-2012-6685 [HIGH] Nokogiri is vulnerable to XML External Entity (XXE) attack
Nokogiri is vulnerable to XML External Entity (XXE) attack
Nokogiri before 1.5.4 is vulnerable to XXE attacks.
GHSA
Nokogiri is vulnerable to XML External Entity (XXE) attack
ghsa·2022-04-23
CVE-2012-6685 [HIGH] CWE-776 Nokogiri is vulnerable to XML External Entity (XXE) attack
Nokogiri is vulnerable to XML External Entity (XXE) attack
Nokogiri before 1.5.4 is vulnerable to XXE attacks.
OSV
CVE-2012-6685: Nokogiri before 1
osv·2020-02-19·CVSS 7.5
CVE-2012-6685 [HIGH] CVE-2012-6685: Nokogiri before 1
Nokogiri before 1.5.4 is vulnerable to XXE attacks
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-6685 rubygem-nokogiri: XML eXternal Entity (XXE) flaw [epel-all]
bugzilla·2015-01-05·CVSS 7.5
CVE-2012-6685 [HIGH] CVE-2012-6685 rubygem-nokogiri: XML eXternal Entity (XXE) flaw [epel-all]
CVE-2012-6685 rubygem-nokogiri: XML eXternal Entity (XXE) flaw [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2012-6685 rubygem-nokogiri: XML eXternal Entity (XXE) flaw
bugzilla·2015-01-05·CVSS 7.5
CVE-2012-6685 [HIGH] CVE-2012-6685 rubygem-nokogiri: XML eXternal Entity (XXE) flaw
CVE-2012-6685 rubygem-nokogiri: XML eXternal Entity (XXE) flaw
An XML eXternal Entity (XXE) flaw was found in Nokogiri, a Ruby gem for parsing HTML, XML, and SAX. Using external XML entities, a remote attacker could specify a URL in a specially crafted XML that, when parsed, would cause a connection to that URL to be opened.
A patch shipped with the 1.5.4 release of Nokogiri provided a "nonet" option to disable external connections. However, local file URLs could still be used to exploit this flaw. The 1.6.4 release of Nokogiri fixed this issue by using libxml2 2.9.0.
Additional information is detailed at:
https://github.com/sparklemotion/nokogiri/issues/693#issuecomment-68334768
CVE request and assignment:
http://seclists.org/oss-sec/2015/q1/57
Discussion:
Created rubygem-nokogiri
Bugzilla
CVE-2012-6685 rubygem-nokogiri: XML eXternal Entity (XXE) flaw [fedora-19]
bugzilla·2015-01-05·CVSS 7.5
CVE-2012-6685 [HIGH] CVE-2012-6685 rubygem-nokogiri: XML eXternal Entity (XXE) flaw [fedora-19]
CVE-2012-6685 rubygem-nokogiri: XML eXternal Entity (XXE) flaw [fedora-19]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
fedora-19 tracking bug for rubygem-nokogiri: see blocks bug
https://bugzilla.redhat.com/show_bug.cgi?id=1178970https://github.com/sparklemotion/nokogiri/issues/693https://nokogiri.org/CHANGELOG.html#154-2012-06-12https://bugzilla.redhat.com/show_bug.cgi?id=1178970https://github.com/sparklemotion/nokogiri/issues/693https://nokogiri.org/CHANGELOG.html#154-2012-06-12
2020-02-19
Published