cbcvebase.
CVE-2020-26247
published 2020-12-30

CVE-2020-26247: Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE…

PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
1.11%
62.4th percentile
Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianruby-nokogiri< ruby-nokogiri 1.11.1+dfsg-1 (bookworm)ruby-nokogiri 1.11.1+dfsg-1 (bookworm)
nokogirinokogiri< 1.19.41.19.4
nokogirinokogiri< 1.11.01.11.0
nokogirinokogiri
nokogirinokogiri>= 0 < 1.19.41.19.4
nokogirinokogiri>= 0 < 1.11.01.11.0
sparklemotionnokogiri< 1.19.41.19.4

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
ghsa4.3MEDIUM
osv4.3MEDIUM
vendor_debian2.6LOW
vendor_redhat2.6LOW
vendor_ubuntu2.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.