File tree Expand file tree Collapse file tree 2 files changed +46
-0
lines changed Expand file tree Collapse file tree 2 files changed +46
-0
lines changed Original file line number Diff line number Diff line change
1
+ ---
2
+ gem : nokogiri
3
+ cve : 2019-5477
4
+ date : 2019-08-11
5
+ url : https://github.com/sparklemotion/nokogiri/issues/1915
6
+ title : Nokogiri Command Injection Vulnerability via Nokogiri::CSS::Tokenizer#load_file
7
+ description : |
8
+ A command injection vulnerability in Nokogiri v1.10.3 and earlier allows
9
+ commands to be executed in a subprocess by Ruby's `Kernel.open` method.
10
+ Processes are vulnerable only if the undocumented method
11
+ `Nokogiri::CSS::Tokenizer#load_file` is being passed untrusted user input.
12
+
13
+ This vulnerability appears in code generated by the Rexical gem versions
14
+ v1.0.6 and earlier. Rexical is used by Nokogiri to generate lexical scanner
15
+ code for parsing CSS queries. The underlying vulnerability was addressed in
16
+ Rexical v1.0.7 and Nokogiri upgraded to this version of Rexical in
17
+ Nokogiri v1.10.4.
18
+
19
+ Upgrade to Nokogiri v1.10.4, or avoid calling the undocumented method
20
+ `Nokogiri::CSS::Tokenizer#load_file` with untrusted user input.
21
+
22
+ patched_versions :
23
+ - " >= 1.10.4"
24
+
25
+ related :
26
+ url :
27
+ - https://github.com/tenderlove/rexical/commit/a652474dbc66be350055db3e8f9b3a7b3fd75926
28
+ - https://groups.google.com/forum/#!msg/ruby-security-ann/YMnKFsASOAE/Fw3ocLI0BQAJ
Original file line number Diff line number Diff line change
1
+ ---
2
+ gem : rexical
3
+ cve : 2019-5477
4
+ date : 2019-08-11
5
+ url : https://github.com/tenderlove/rexical/commit/a652474dbc66be350055db3e8f9b3a7b3fd75926
6
+ title : Rexical Command Injection Vulnerability
7
+ description : |
8
+ A command injection vulnerability appears in code generated by the Rexical
9
+ gem versions v1.0.6 and earlier. It allows commands to be executed in a
10
+ subprocess by Ruby's `Kernel.open` method.
11
+
12
+ patched_versions :
13
+ - " >= 1.0.7"
14
+
15
+ related :
16
+ url :
17
+ - https://github.com/tenderlove/rexical/blob/master/CHANGELOG.rdoc#107--2019-08-06
18
+ - https://groups.google.com/forum/#!msg/ruby-security-ann/YMnKFsASOAE/Fw3ocLI0BQAJ
You can’t perform that action at this time.
0 commit comments