XML Injection in Xerces Java affects Nokogiri
Moderate severity
GitHub Reviewed
Published
Apr 11, 2022
in
sparklemotion/nokogiri
•
Updated Jan 11, 2023
Description
Published to the GitHub Advisory Database
Apr 11, 2022
Reviewed
Apr 11, 2022
Last updated
Jan 11, 2023
Summary
Nokogiri v1.13.4 updates the vendored
xerces:xercesImpl
from 2.12.0 to 2.12.2, which addresses CVE-2022-23437. That CVE is scored as CVSS 6.5 "Medium" on the NVD record.Please note that this advisory only applies to the JRuby implementation of Nokogiri
< 1.13.4
.Mitigation
Upgrade to Nokogiri
>= v1.13.4
.Impact
CVE-2022-23437 in xerces-J
References