CVE Vulnerabilities

CVE-2012-6685

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

Published: Feb 19, 2020 | Modified: Jul 15, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM

Nokogiri before 1.5.4 is vulnerable to XXE attacks

Weakness

The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.

Affected Software

Name Vendor Start Version End Version
Nokogiri Nokogiri * 1.5.4 (excluding)
CloudForms Management Engine 5.10 RedHat ansible-runner-0:1.1.2-2.el7ar *
CloudForms Management Engine 5.10 RedHat ansible-tower-0:3.3.3-1.el7at *
CloudForms Management Engine 5.10 RedHat bubblewrap-0:0.1.7-1.el7 *
CloudForms Management Engine 5.10 RedHat cfme-0:5.10.0.33-1.el7cf *
CloudForms Management Engine 5.10 RedHat cfme-amazon-smartstate-0:5.10.0.33-1.el7cf *
CloudForms Management Engine 5.10 RedHat cfme-appliance-0:5.10.0.33-1.el7cf *
CloudForms Management Engine 5.10 RedHat cfme-gemset-0:5.10.0.33-1.el7cf *
CloudForms Management Engine 5.10 RedHat dbus-api-service-0:1.0.1-5.el7cf *
CloudForms Management Engine 5.10 RedHat dumb-init-0:1.2.0-1.el7cf *
CloudForms Management Engine 5.10 RedHat erlang-0:19.3.6.7-1.el7at *
CloudForms Management Engine 5.10 RedHat google-compute-engine-0:2.0.0-2.el7cf *
CloudForms Management Engine 5.10 RedHat google-config-0:2.0.0-2.el7cf *
CloudForms Management Engine 5.10 RedHat httpd-configmap-generator-0:0.2.2-2.el7cf *
CloudForms Management Engine 5.10 RedHat nginx-1:1.10.2-1.el7at *
CloudForms Management Engine 5.10 RedHat ovirt-ansible-cluster-upgrade-0:1.1.8-1.el7ev *
CloudForms Management Engine 5.10 RedHat ovirt-ansible-disaster-recovery-0:1.1.2-1.el7ev *
CloudForms Management Engine 5.10 RedHat ovirt-ansible-engine-setup-0:1.1.5-1.el7ev *
CloudForms Management Engine 5.10 RedHat ovirt-ansible-image-template-0:1.1.8-1.el7ev *
CloudForms Management Engine 5.10 RedHat ovirt-ansible-infra-0:1.1.8-1.el7ev *
CloudForms Management Engine 5.10 RedHat ovirt-ansible-manageiq-0:1.1.12-1.el7ev *
CloudForms Management Engine 5.10 RedHat ovirt-ansible-repositories-0:1.1.2-1.el7ev *
CloudForms Management Engine 5.10 RedHat ovirt-ansible-roles-0:1.1.5-1.el7ev *
CloudForms Management Engine 5.10 RedHat ovirt-ansible-shutdown-env-0:1.0.0-1.el7ev *
CloudForms Management Engine 5.10 RedHat ovirt-ansible-v2v-conversion-host-0:1.6.3-1.el7ev *
CloudForms Management Engine 5.10 RedHat ovirt-ansible-vm-infra-0:1.1.10-1.el7ev *
CloudForms Management Engine 5.10 RedHat postgresql96-0:9.6.10-1PGDG.el7at *
CloudForms Management Engine 5.10 RedHat prince-0:9.0r2-10.el7cf *
CloudForms Management Engine 5.10 RedHat pyOpenSSL-0:17.3.0-4.el7ost *
CloudForms Management Engine 5.10 RedHat python-bambou-0:3.0.1-2.el7cf *
CloudForms Management Engine 5.10 RedHat python-colorama-0:0.3.7-2.el7ost *
CloudForms Management Engine 5.10 RedHat python-crypto-0:2.6.1-16.el7at *
CloudForms Management Engine 5.10 RedHat python-daemon-0:2.1.2-7.el7at *
CloudForms Management Engine 5.10 RedHat python-funcsigs-0:1.0.2-1.el7ost *
CloudForms Management Engine 5.10 RedHat python-future-0:0.16.0-1.el7cf *
CloudForms Management Engine 5.10 RedHat python-lockfile-1:0.11.0-10.el7at *
CloudForms Management Engine 5.10 RedHat python-meld3-0:0.6.10-1.el7 *
CloudForms Management Engine 5.10 RedHat python-mock-0:2.0.0-1.el7ost *
CloudForms Management Engine 5.10 RedHat python-pbr-0:3.1.1-2.el7ost *
CloudForms Management Engine 5.10 RedHat python-pexpect-0:4.6-1.el7at *
CloudForms Management Engine 5.10 RedHat python-psutil-0:5.4.3-2.el7at *
CloudForms Management Engine 5.10 RedHat python-ptyprocess-0:0.5.2-3.el7at *
CloudForms Management Engine 5.10 RedHat python-pylxca-0:2.1.1-2.el7cf *
CloudForms Management Engine 5.10 RedHat python-pysocks-0:1.5.6-3.el7ost *
CloudForms Management Engine 5.10 RedHat python-requests-0:2.14.2-1.el7ost *
CloudForms Management Engine 5.10 RedHat python-requests-toolbelt-0:0.8.0-2.el7cf *
CloudForms Management Engine 5.10 RedHat python-tabulate-0:0.8.2-1.el7cf *
CloudForms Management Engine 5.10 RedHat python-urllib3-0:1.21.1-1.2.el7ost *
CloudForms Management Engine 5.10 RedHat python-vspk-0:5.3.2-2.el7cf *
CloudForms Management Engine 5.10 RedHat qpid-proton-0:0.19.0-1.el7cf *
CloudForms Management Engine 5.10 RedHat rabbitmq-server-0:3.7.4-1.el7at *
CloudForms Management Engine 5.10 RedHat rh-postgresql95-postgresql-pglogical-0:2.1.0-4.el7cf *
CloudForms Management Engine 5.10 RedHat rh-postgresql95-repmgr-0:4.0.6-2.el7cf *
CloudForms Management Engine 5.10 RedHat ruby-0:2.4.5-90.el7cf *
CloudForms Management Engine 5.10 RedHat rubygem-bcrypt-0:3.1.12-1.el7cf *
CloudForms Management Engine 5.10 RedHat rubygem-ffi-0:1.9.25-1.el7cf *
CloudForms Management Engine 5.10 RedHat rubygem-hamlit-0:2.8.8-1.el7cf *
CloudForms Management Engine 5.10 RedHat rubygem-http_parser.rb-0:0.6.0-1.el7cf *
CloudForms Management Engine 5.10 RedHat rubygem-json-0:2.1.0-1.el7cf *
CloudForms Management Engine 5.10 RedHat rubygem-linux_block_device-0:0.2.1-1.el7cf *
CloudForms Management Engine 5.10 RedHat rubygem-memory_buffer-0:0.1.0-2.el7cf *
CloudForms Management Engine 5.10 RedHat rubygem-nio4r-0:2.3.1-1.el7cf *
CloudForms Management Engine 5.10 RedHat rubygem-nokogiri-0:1.8.2-1.el7cf *
CloudForms Management Engine 5.10 RedHat rubygem-ovirt-engine-sdk4-0:4.2.4-1.el7cf *
CloudForms Management Engine 5.10 RedHat rubygem-pg-0:0.18.4-2.el7cf *
CloudForms Management Engine 5.10 RedHat rubygem-puma-0:3.7.1-1.el7cf *
CloudForms Management Engine 5.10 RedHat rubygem-qpid_proton-0:0.22.0-2.el7cf *
CloudForms Management Engine 5.10 RedHat rubygem-redhat_access_cfme-0:2.0.3-1.el7cf *
CloudForms Management Engine 5.10 RedHat rubygem-redhat_access_lib-0:1.1.4-2.el7cf *
CloudForms Management Engine 5.10 RedHat rubygem-rugged-0:0.27.4-1.el7cf *
CloudForms Management Engine 5.10 RedHat rubygem-sqlite3-0:1.3.13-2.el7cf *
CloudForms Management Engine 5.10 RedHat rubygem-unf_ext-0:0.0.7.5-1.el7cf *
CloudForms Management Engine 5.10 RedHat rubygem-websocket-driver-0:0.6.5-1.el7cf *
CloudForms Management Engine 5.10 RedHat smem-0:1.4-1.el7cf *
CloudForms Management Engine 5.10 RedHat supervisor-0:3.1.4-1.el7 *
CloudForms Management Engine 5.10 RedHat wmi-0:1.3.14-7.el7cf *
CloudForms Management Engine 5.10 RedHat wxGTK3-0:3.0.3-5.el7at *
Libnokogiri-ruby Ubuntu lucid *
Ruby-nokogiri Ubuntu precise *
Ruby-nokogiri Ubuntu upstream *

Potential Mitigations

References