CVE-2021-3537

MEDIUM5.9EPSS 0.11%

Nokogiri Implements libxml2 version vulnerable to null pointer dereferencing

發布日:2022/5/24修改日:2025/12/3
也稱為:GHSA-286v-pcf5-25rcALPINE-CVE-2021-3537

描述

A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this vulnerability is to system availability.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

參考連結(16)