Nokogiri Gem for JRuby XML Document Root Element Handling Memory Consumption Remote DoS
Published: April 30, 2014
SECURITY IDENTIFIERS
- OSVDB: OSVDB-118481
- Vendor Advisory: https://github.com/sparklemotion/nokogiri/pull/1087
GEM
PLATFORM
PATCHED VERSIONS
~> 1.6.2.2
>= 1.6.3
DESCRIPTION
Nokogiri Gem for JRuby contains a flaw that is triggered when handling a root element in an XML document. This may allow a remote attacker to cause a consumption of memory resources.
