GHSA-jmhh-w7xp-wg39

Suggest an improvement
Source
https://github.com/advisories/GHSA-jmhh-w7xp-wg39
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jmhh-w7xp-wg39/GHSA-jmhh-w7xp-wg39.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jmhh-w7xp-wg39
Aliases
  • CVE-2013-6461
Published
2022-05-05T00:29:01Z
Modified
2024-02-16T08:17:18Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Nokogiri vulnerable to DoS while parsing XML entities
Details

Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits

Database specific
{
    "cwe_ids": [
        "CWE-776"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2023-06-09T19:45:09Z",
    "nvd_published_at": "2019-11-05T15:15:00Z",
    "severity": "MODERATE"
}
References

Affected packages

RubyGems / nokogiri

Package

Name
nokogiri
Purl
pkg:gem/nokogiri

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.5.0
Fixed
1.5.11

Affected versions

1.*
1.5.0
1.5.1.rc1
1.5.1
1.5.2
1.5.3.rc2
1.5.3.rc3
1.5.3.rc4
1.5.3.rc5
1.5.3.rc6
1.5.3
1.5.4.rc1
1.5.4.rc2
1.5.4.rc3
1.5.4
1.5.5.rc1
1.5.5.rc2
1.5.5.rc3
1.5.5
1.5.6.rc1
1.5.6.rc2
1.5.6.rc3
1.5.6
1.5.7.rc1
1.5.7.rc2
1.5.7.rc3
1.5.7
1.5.8
1.5.9
1.5.10

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jmhh-w7xp-wg39/GHSA-jmhh-w7xp-wg39.json"

RubyGems / nokogiri

Package

Name
nokogiri
Purl
pkg:gem/nokogiri

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.6.0
Fixed
1.6.1

Affected versions

1.*
1.6.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jmhh-w7xp-wg39/GHSA-jmhh-w7xp-wg39.json"