VDB
KO
CRITICAL 9.8

GHSA-qxcg-xjjg-66mj

Nokogiri vulnerable to libxslt protection mechanism bypass

Details

A dependency of Nokogiri, libxslt through 1.1.33 allows bypass of a protection mechanism because callers of `xsltCheckRead` and `xsltCheckWrite` permit access even upon receiving a `-1` error code. `xsltCheckRead` can return `-1` for a crafted URL that is not actually invalid and is subsequently loaded.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems / nokogiri
Introduced in: 0 Fixed in: 1.10.3
Fix bundle update nokogiri

References