Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Nokogiri XXE vulnerability #31

Closed
brynary opened this issue Mar 7, 2013 · 3 comments
Closed

Add Nokogiri XXE vulnerability #31

brynary opened this issue Mar 7, 2013 · 3 comments
Labels

Comments

@brynary
Copy link
Member

brynary commented Mar 7, 2013

sparklemotion/nokogiri#693

Network vulnerability fixed in Nokogiri v1.5.4:

http://www.ruby-forum.com/topic/4402659

Not sure when local filesystem vulnerability was fixed.

@skorth
Copy link
Contributor

skorth commented Nov 3, 2014

The local filesystem vuln. was fixed within libxml2 version 2.9.x. Meanwhile they added 2.9.x as dependency https://github.com/sparklemotion/nokogiri/blob/master/dependencies.yml.

@reedloden
Copy link
Member

https://github.com/rubysec/ruby-advisory-db/blob/master/gems/nokogiri/OSVDB-90946.yml was added a while ago. Does that address this? I know it's really two separate issues, but I only see the one CVE / OSVDB assignment.

@mveytsman
Copy link
Member

I believe 90946 covers this

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants