CVE-2023-46035

Summary

The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.

Affected Software

VendorProductVersion RangeStatus
fnandosvg_optimizer0 < 0.3.0affected

Weaknesses

  • CWE-776: CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References