Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-20505
HistorySep 29, 2021 - 12:00 a.m.

Nokogiri code issue vulnerability

2021-09-2900:00:00
China National Vulnerability Database
www.cnvd.org.cn
16

0.001 Low

EPSS

Percentile

49.1%

Nokogiri is an open source software library for parsing HTML and XML in Ruby. a code issue vulnerability exists in Nokogiri, which stems from the fact that in Nokogiri v1.12.4 and earlier versions, on JRuby only, the SAX parser parses external entities by default. No details of the vulnerability are currently available.

CPENameOperatorVersion
nokogiri nokogirile1.12.4