MODERATERubyGems →
Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12
Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12
Affected packages
- nokogiri— before 1.11.4
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-7rrm-v45f-jp64
- https://nvd.nist.gov/vuln/detail/CVE-2021-3541
- https://github.com/sparklemotion/nokogiri/commit/9b90a8854f74b5f672a437ba0043a503bc259d1b
- https://github.com/sparklemotion/nokogiri
Structured record: https://osv.dev/vulnerability/GHSA-7rrm-v45f-jp64
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta