All vulnerabilities

CVE-2021-3537

Nokogiri Implements libxml2 version vulnerable to null pointer dereferencing

Description

A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this vulnerability is to system availability.

Patch Available

Fix available through Seal Security. 

No upgrade required, protect your application instantly.

Fix without upgrading
Score
Severity
Ecosystem
RPM
Publish Date
May 24, 2022
Modified Date
February 20, 2024
Score Vector
Affected Versions