XML injection (XXE) In nokogiri
Description
Nokogiri vulnerable to DoS while parsing XML entities Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rubygems | 1.5.11, 1.6.1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5.