Lucene search

K
osvGoogleOSV:GHSA-QXCG-XJJG-66MJ
HistoryMay 13, 2022 - 1:21 a.m.

Nokogiri vulnerable to libxslt protection mechanism bypass

2022-05-1301:21:57
Google
osv.dev
7

0.003 Low

EPSS

Percentile

65.5%

A dependency of Nokogiri, libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

References