Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
계획된 패치 주기 내 조치(60일 이내)
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N약점 (CWE)
- CWE-611
XML 외부 엔티티(XXE) — 외부 엔티티 처리로 파일 노출·SSRF·DoS.
상세 설명
Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- nokogiri nokogiri< 1.11.0other
- nokogiri nokogiriother
- nokogiri nokogiriother
- nokogiri nokogiriother
- debian debian_linuxlinux
- debian debian_linuxlinux
영향받는 구성 (CPE) 6
- nokogiri nokogiri< 1.11.0cpe:2.3:a:nokogiri:nokogiri:*:*:*:*:*:ruby:*:*
- nokogiri nokogiri 1.11.0cpe:2.3:a:nokogiri:nokogiri:1.11.0:rc1:*:*:*:ruby:*:*
- nokogiri nokogiri 1.11.0cpe:2.3:a:nokogiri:nokogiri:1.11.0:rc2:*:*:*:ruby:*:*
- nokogiri nokogiri 1.11.0cpe:2.3:a:nokogiri:nokogiri:1.11.0:rc3:*:*:*:ruby:*:*
- debian debian_linux 9.0cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
- debian debian_linux 10.0cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
참고 자료 8
- https://github.com/sparklemotion/nokogiri/commit/9c87439d9afa14a365ff13e73adc809cb2c3d97bPatchThird Party Advisory
- https://github.com/sparklemotion/nokogiri/releases/tag/v1.11.0.rc4Release NotesThird Party Advisory
- https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-vr8q-g5c7-m54mMitigationThird Party Advisory
- https://hackerone.com/reports/747489Permissions Required
- https://lists.debian.org/debian-lts-announce/2021/06/msg00007.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00018.htmlMailing ListThird Party Advisory
- https://rubygems.org/gems/nokogiriProductThird Party Advisory
- https://security.gentoo.org/glsa/202208-29Third Party Advisory
링크 내용 불러오는 중…