Nokogiri before 1.5.4 is vulnerable to XXE attacks
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
Link | Tags |
---|---|
https://github.com/sparklemotion/nokogiri/issues/693 | issue tracking exploit third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1178970 | issue tracking third party advisory |
https://nokogiri.org/CHANGELOG.html#154-2012-06-12 | release notes vendor advisory |