PT-2020-5511 · Nokogiri+5 · Nokogiri+5

Published

2020-12-30

·

Updated

2025-08-25

·

CVE-2020-26247

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nokogiri versions prior to 1.11.0.rc4 Nokogiri versions 1.10.10 and earlier Nokogiri prereleases 1.11.0.rc1, 1.11.0.rc2, and 1.11.0.rc3
Description The issue is related to the incorrect restriction of XML links to external objects, allowing external resources to be accessed over the network. This could potentially enable XXE or SSRF attacks. The behavior of trusting XML Schemas parsed by Nokogiri::XML::Schema by default is counter to the security policy of treating all input as untrusted by default.
Recommendations For Nokogiri versions prior to 1.11.0.rc4, upgrade to Nokogiri version 1.11.0.rc4 or later. If you wish to re-enable network access for resolution of external resources after upgrading, ensure the input is trusted and pass an instance of Nokogiri::XML::ParseOptions with the NONET flag turned off when invoking the Nokogiri::XML::Schema constructor. As a temporary workaround, consider restricting access to external resources until the issue is resolved.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

BDU:2021-01008
CVE-2020-26247
DLA-2678-1
DLA-3149-1
GHSA-VR8Q-G5C7-M54M
MGASA-2021-0063
OESA-2021-1144
OPENSUSE-SU-2021:0237-1
OPENSUSE-SU-2021_0237-1
RHSA-2021:4702
SUSE-SU-2021:0210-1
SUSE-SU-2021:0251-1
SUSE-SU-2021:2554-1
USN-7659-1

Affected Products

Astra Linux
Linuxmint
Nokogiri
Red Os
Suse
Ubuntu