XML injection (XXE) In nokogiri
Description
Nokogiri vulnerable to DoS while parsing XML documents Nokogiri gem has Denial of Service via infinite loop when parsing XML documents
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rubygems | 1.5.11, 1.6.1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6.