CVE-2019-5477
Last modified
CVE-2019-5477 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::Tokenizer#load_file` is being called with unsafe user input as the filename. EPSS estimates a 5.90% chance of exploitation in the next 30 days.
Description
A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::Tokenizer#load_file` is being called with unsafe user input as the filename. This vulnerability appears in code generated by the Rexical gem versions v1.0.6 and earlier. Rexical is used by Nokogiri to generate lexical scanner code for parsing CSS queries. The underlying vulnerability was addressed in Rexical v1.0.7 and Nokogiri upgraded to this version of Rexical in Nokogiri v1.10.4.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nokogiri | Nokogiri | <= 1.10.3 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 19.04 |
| Canonical | Ubuntu Linux | 19.10 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 10.0 |
References
- https://github.com/sparklemotion/nokogiri/issues/1915Patch, Third Party Advisory
- https://hackerone.com/reports/650835Permissions Required
- https://lists.debian.org/debian-lts-announce/2019/09/msg00027.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00018.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00019.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202006-05Third Party Advisory
- https://usn.ubuntu.com/4175-1/Third Party Advisory
- https://github.com/sparklemotion/nokogiri/issues/1915Patch, Third Party Advisory
- https://hackerone.com/reports/650835Permissions Required
- https://lists.debian.org/debian-lts-announce/2019/09/msg00027.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00018.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00019.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202006-05Third Party Advisory
- https://usn.ubuntu.com/4175-1/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-5477?
How severe is CVE-2019-5477?
How do I fix CVE-2019-5477?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-5471An input validation and output encoding issue was discovered…5.4
- CVE-2019-5472An authorization issue was discovered in Gitlab versions < 1…7.5
- CVE-2019-5473An authentication issue was discovered in GitLab that allowe…7.2
- CVE-2019-5474An authorization issue was discovered in GitLab EE < 12.1.2,…6.5
- CVE-2019-5475The Nexus Yum Repository Plugin in v2 is vulnerable to Remot…
- CVE-2019-5476An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (ru…9.8
- CVE-2019-5478A weakness was found in Encrypt Only boot mode in Zynq Ultra…5.5
- CVE-2019-5479An unintended require vulnerability in <v0.5.5 larvitbase-ap…7.5
- CVE-2019-5480A path traversal vulnerability in <= v0.9.7 of statichttpser…
- CVE-2019-5481Double-free vulnerability in the FTP-kerberos code in cURL 7…9.8
- CVE-2019-5482Heap buffer overflow in the TFTP protocol handler in cURL 7.…9.8
- CVE-2019-5483Seneca < 3.9.0 contains a vulnerability that could lead to e…5.3
Are you affected by CVE-2019-5477?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
