A vulnerability was found in Nokogiri up to 1.12.4 on Ruby (Ruby Gem). It has been rated as critical. This issue affects the function Nokogiri::XML::SAX::Parse/Nokogiri::HTML4::SAX::Parser/its alias Nokogiri::HTML::SAX::Parser/Nokogiri::XML::SAX::PushParser/Nokogiri::HTML4::SAX::PushParser/Nokogiri::HTML::SAX::PushParser
of the component SAX Parser. Upgrading to version 1.12.5 eliminates this vulnerability. Applying the patch 5bf729ff3cc84709ee3c3248c981584088bf9f6d is able to eliminate this problem. The bugfix is ready for download at github.com. The best possible mitigation is suggested to be upgrading to the latest version.
Nokogiri up to 1.12.4 on Ruby SAX Parser PushParser xml external entity reference
CVE-2024-12728 : SOPHOS FIREWALL UP TO 20.0 MR2 SSH WEAK CREDENTIALS
Description A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than version 20.0 MR3
CVE-2021-26102 : FORTINET FORTIWAN UP TO 4.4.1/4.5.7 POST REQUEST AUTHENTICATION BYPASS
Description A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote
CVE-2024-35141 : IBM SECURITY VERIFY ACCESS DOCKER UP TO 10.0.6 UNNECESSARY PRIVILEGES
Description IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to