VDB
KO
MEDIUM 6.5

GHSA-jmhh-w7xp-wg39

Nokogiri vulnerable to DoS while parsing XML entities

Details

Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems / nokogiri
Introduced in: 1.5.0 Fixed in: 1.5.11
Fix bundle update nokogiri
RubyGems / nokogiri
Introduced in: 1.6.0 Fixed in: 1.6.1
Fix bundle update nokogiri

References