<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">Security update for rubygem-nokogiri</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2021:0251-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2021-02-01T10:20:05Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-02-01T10:20:05Z</InitialReleaseDate>
    <CurrentReleaseDate>2021-02-01T10:20:05Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for rubygem-nokogiri</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for rubygem-nokogiri fixes the following issues:
  
rubygem-nokogiri was updated to 1.8.5 (bsc#1156722).

Security issues fixed:

- CVE-2019-5477: Fixed a command injection vulnerability (bsc#1146578).
- CVE-2020-26247: Fixed an XXE vulnerability in Nokogiri::XML::Schema (bsc#1180507).
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">Image SLES15-SP3-BYOS-Azure-2021-251,Image SLES15-SP3-BYOS-EC2-HVM-2021-251,Image SLES15-SP3-BYOS-GCE-2021-251,Image SLES15-SP3-EC2-HVM-2021-251,Image SLES15-SP3-GCE-2021-251,Image SLES15-SP3-HPC-Azure-2021-251,Image SLES15-SP3-HPC-BYOS-Azure-2021-251,Image SLES15-SP3-HPC-BYOS-EC2-HVM-2021-251,Image SLES15-SP3-HPC-BYOS-GCE-2021-251,Image SLES15-SP3-Manager-4-2-Proxy-BYOS-Azure-2021-251,Image SLES15-SP3-Manager-4-2-Proxy-BYOS-EC2-HVM-2021-251,Image SLES15-SP3-Manager-4-2-Proxy-BYOS-GCE-2021-251,Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure-2021-251,Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM-2021-251,Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE-2021-251,Image SLES15-SP3-SAP-Azure-2021-251,Image SLES15-SP3-SAP-Azure-LI-BYOS-Production-2021-251,Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production-2021-251,Image SLES15-SP3-SAP-BYOS-Azure-2021-251,Image SLES15-SP3-SAP-BYOS-EC2-HVM-2021-251,Image SLES15-SP3-SAP-BYOS-GCE-2021-251,Image SLES15-SP3-SAP-EC2-HVM-2021-251,Image SLES15-SP3-SAP-GCE-2021-251,Image SLES15-SP3-SAPCAL-Azure-2021-251,Image SLES15-SP3-SAPCAL-EC2-HVM-2021-251,Image SLES15-SP3-SAPCAL-GCE-2021-251,SUSE-2021-251,SUSE-SLE-Product-HA-15-2021-251,SUSE-SLE-Product-HA-15-SP1-2021-251,SUSE-SLE-Product-HA-15-SP2-2021-251</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20210251-1/</URL>
      <Description>Link for SUSE-SU-2021:0251-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2021-February/008258.html</URL>
      <Description>E-Mail link for SUSE-SU-2021:0251-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1146578</URL>
      <Description>SUSE Bug 1146578</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1156722</URL>
      <Description>SUSE Bug 1156722</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1180507</URL>
      <Description>SUSE Bug 1180507</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-5477/</URL>
      <Description>SUSE CVE CVE-2019-5477 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-26247/</URL>
      <Description>SUSE CVE CVE-2020-26247 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="Image SLES15-SP3-BYOS-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP3-BYOS-Azure">
        <FullProductName ProductID="Image SLES15-SP3-BYOS-Azure">Image SLES15-SP3-BYOS-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-BYOS-EC2-HVM">
      <Branch Type="Product Name" Name="Image SLES15-SP3-BYOS-EC2-HVM">
        <FullProductName ProductID="Image SLES15-SP3-BYOS-EC2-HVM">Image SLES15-SP3-BYOS-EC2-HVM</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-BYOS-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP3-BYOS-GCE">
        <FullProductName ProductID="Image SLES15-SP3-BYOS-GCE">Image SLES15-SP3-BYOS-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-EC2-HVM">
      <Branch Type="Product Name" Name="Image SLES15-SP3-EC2-HVM">
        <FullProductName ProductID="Image SLES15-SP3-EC2-HVM">Image SLES15-SP3-EC2-HVM</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP3-GCE">
        <FullProductName ProductID="Image SLES15-SP3-GCE">Image SLES15-SP3-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-HPC-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP3-HPC-Azure">
        <FullProductName ProductID="Image SLES15-SP3-HPC-Azure">Image SLES15-SP3-HPC-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-HPC-BYOS-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP3-HPC-BYOS-Azure">
        <FullProductName ProductID="Image SLES15-SP3-HPC-BYOS-Azure">Image SLES15-SP3-HPC-BYOS-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-HPC-BYOS-EC2-HVM">
      <Branch Type="Product Name" Name="Image SLES15-SP3-HPC-BYOS-EC2-HVM">
        <FullProductName ProductID="Image SLES15-SP3-HPC-BYOS-EC2-HVM">Image SLES15-SP3-HPC-BYOS-EC2-HVM</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-HPC-BYOS-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP3-HPC-BYOS-GCE">
        <FullProductName ProductID="Image SLES15-SP3-HPC-BYOS-GCE">Image SLES15-SP3-HPC-BYOS-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-Manager-4-2-Proxy-BYOS-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP3-Manager-4-2-Proxy-BYOS-Azure">
        <FullProductName ProductID="Image SLES15-SP3-Manager-4-2-Proxy-BYOS-Azure">Image SLES15-SP3-Manager-4-2-Proxy-BYOS-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-Manager-4-2-Proxy-BYOS-EC2-HVM">
      <Branch Type="Product Name" Name="Image SLES15-SP3-Manager-4-2-Proxy-BYOS-EC2-HVM">
        <FullProductName ProductID="Image SLES15-SP3-Manager-4-2-Proxy-BYOS-EC2-HVM">Image SLES15-SP3-Manager-4-2-Proxy-BYOS-EC2-HVM</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-Manager-4-2-Proxy-BYOS-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP3-Manager-4-2-Proxy-BYOS-GCE">
        <FullProductName ProductID="Image SLES15-SP3-Manager-4-2-Proxy-BYOS-GCE">Image SLES15-SP3-Manager-4-2-Proxy-BYOS-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure">
        <FullProductName ProductID="Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure">Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM">
      <Branch Type="Product Name" Name="Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM">
        <FullProductName ProductID="Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM">Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE">
        <FullProductName ProductID="Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE">Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-SAP-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP3-SAP-Azure">
        <FullProductName ProductID="Image SLES15-SP3-SAP-Azure">Image SLES15-SP3-SAP-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-SAP-Azure-LI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES15-SP3-SAP-Azure-LI-BYOS-Production">
        <FullProductName ProductID="Image SLES15-SP3-SAP-Azure-LI-BYOS-Production">Image SLES15-SP3-SAP-Azure-LI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production">
        <FullProductName ProductID="Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production">Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-SAP-BYOS-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP3-SAP-BYOS-Azure">
        <FullProductName ProductID="Image SLES15-SP3-SAP-BYOS-Azure">Image SLES15-SP3-SAP-BYOS-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-SAP-BYOS-EC2-HVM">
      <Branch Type="Product Name" Name="Image SLES15-SP3-SAP-BYOS-EC2-HVM">
        <FullProductName ProductID="Image SLES15-SP3-SAP-BYOS-EC2-HVM">Image SLES15-SP3-SAP-BYOS-EC2-HVM</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-SAP-BYOS-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP3-SAP-BYOS-GCE">
        <FullProductName ProductID="Image SLES15-SP3-SAP-BYOS-GCE">Image SLES15-SP3-SAP-BYOS-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-SAP-EC2-HVM">
      <Branch Type="Product Name" Name="Image SLES15-SP3-SAP-EC2-HVM">
        <FullProductName ProductID="Image SLES15-SP3-SAP-EC2-HVM">Image SLES15-SP3-SAP-EC2-HVM</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-SAP-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP3-SAP-GCE">
        <FullProductName ProductID="Image SLES15-SP3-SAP-GCE">Image SLES15-SP3-SAP-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-SAPCAL-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP3-SAPCAL-Azure">
        <FullProductName ProductID="Image SLES15-SP3-SAPCAL-Azure">Image SLES15-SP3-SAPCAL-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-SAPCAL-EC2-HVM">
      <Branch Type="Product Name" Name="Image SLES15-SP3-SAPCAL-EC2-HVM">
        <FullProductName ProductID="Image SLES15-SP3-SAPCAL-EC2-HVM">Image SLES15-SP3-SAPCAL-EC2-HVM</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-SAPCAL-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP3-SAPCAL-GCE">
        <FullProductName ProductID="Image SLES15-SP3-SAPCAL-GCE">Image SLES15-SP3-SAPCAL-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Availability Extension 15">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Availability Extension 15">
        <FullProductName ProductID="SUSE Linux Enterprise High Availability Extension 15" CPE="cpe:/o:suse:sle-ha:15">SUSE Linux Enterprise High Availability Extension 15</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Availability Extension 15 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Availability Extension 15 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise High Availability Extension 15 SP1" CPE="cpe:/o:suse:sle-ha:15:sp1">SUSE Linux Enterprise High Availability Extension 15 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Availability Extension 15 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Availability Extension 15 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise High Availability Extension 15 SP2" CPE="cpe:/o:suse:sle-ha:15:sp2">SUSE Linux Enterprise High Availability Extension 15 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">
      <FullProductName ProductID="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ruby2.5-rubygem-nokogiri-doc-1.8.5-3.6.1">
      <FullProductName ProductID="ruby2.5-rubygem-nokogiri-doc-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-doc-1.8.5-3.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ruby2.5-rubygem-nokogiri-testsuite-1.8.5-3.6.1">
      <FullProductName ProductID="ruby2.5-rubygem-nokogiri-testsuite-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-testsuite-1.8.5-3.6.1</FullProductName>
    </Branch>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP3-BYOS-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-BYOS-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP3-BYOS-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-BYOS-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP3-BYOS-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP3-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-GCE">
      <FullProductName ProductID="Image SLES15-SP3-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-HPC-Azure">
      <FullProductName ProductID="Image SLES15-SP3-HPC-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-HPC-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-HPC-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP3-HPC-BYOS-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-HPC-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-HPC-BYOS-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP3-HPC-BYOS-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-HPC-BYOS-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-HPC-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP3-HPC-BYOS-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-HPC-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-Manager-4-2-Proxy-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP3-Manager-4-2-Proxy-BYOS-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-Manager-4-2-Proxy-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-Manager-4-2-Proxy-BYOS-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP3-Manager-4-2-Proxy-BYOS-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-Manager-4-2-Proxy-BYOS-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-Manager-4-2-Proxy-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP3-Manager-4-2-Proxy-BYOS-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-Manager-4-2-Proxy-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-SAP-Azure">
      <FullProductName ProductID="Image SLES15-SP3-SAP-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-SAP-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-SAP-Azure-LI-BYOS-Production">
      <FullProductName ProductID="Image SLES15-SP3-SAP-Azure-LI-BYOS-Production:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-SAP-Azure-LI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production">
      <FullProductName ProductID="Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-SAP-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP3-SAP-BYOS-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-SAP-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-SAP-BYOS-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP3-SAP-BYOS-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-SAP-BYOS-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-SAP-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP3-SAP-BYOS-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-SAP-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-SAP-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP3-SAP-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-SAP-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-SAP-GCE">
      <FullProductName ProductID="Image SLES15-SP3-SAP-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-SAP-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-SAPCAL-Azure">
      <FullProductName ProductID="Image SLES15-SP3-SAPCAL-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-SAPCAL-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-SAPCAL-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP3-SAPCAL-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-SAPCAL-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-SAPCAL-GCE">
      <FullProductName ProductID="Image SLES15-SP3-SAPCAL-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of Image SLES15-SP3-SAPCAL-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Availability Extension 15">
      <FullProductName ProductID="SUSE Linux Enterprise High Availability Extension 15:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of SUSE Linux Enterprise High Availability Extension 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Availability Extension 15 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise High Availability Extension 15 SP1:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of SUSE Linux Enterprise High Availability Extension 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-nokogiri-1.8.5-3.6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Availability Extension 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise High Availability Extension 15 SP2:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1">ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 as a component of SUSE Linux Enterprise High Availability Extension 15 SP2</FullProductName>
    </Relationship>
  </ProductTree>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::Tokenizer#load_file` is being called with unsafe user input as the filename. This vulnerability appears in code generated by the Rexical gem versions v1.0.6 and earlier. Rexical is used by Nokogiri to generate lexical scanner code for parsing CSS queries. The underlying vulnerability was addressed in Rexical v1.0.7 and Nokogiri upgraded to this version of Rexical in Nokogiri v1.10.4.</Note>
    </Notes>
    <CVE>CVE-2019-5477</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES15-SP3-BYOS-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-BYOS-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-BYOS-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-HPC-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-HPC-BYOS-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-HPC-BYOS-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-HPC-BYOS-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Proxy-BYOS-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Proxy-BYOS-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Proxy-BYOS-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-Azure-LI-BYOS-Production:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-BYOS-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-BYOS-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-BYOS-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAPCAL-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAPCAL-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAPCAL-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 15 SP1:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 15 SP2:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 15:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>7.5</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>8.1</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20210251-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-5477.html</URL>
        <Description>CVE-2019-5477</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1146578</URL>
        <Description>SUSE Bug 1146578</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.</Note>
    </Notes>
    <CVE>CVE-2020-26247</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES15-SP3-BYOS-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-BYOS-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-BYOS-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-HPC-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-HPC-BYOS-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-HPC-BYOS-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-HPC-BYOS-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Proxy-BYOS-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Proxy-BYOS-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Proxy-BYOS-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-Azure-LI-BYOS-Production:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-BYOS-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-BYOS-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-BYOS-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAPCAL-Azure:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAPCAL-EC2-HVM:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>Image SLES15-SP3-SAPCAL-GCE:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 15 SP1:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 15 SP2:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 15:ruby2.5-rubygem-nokogiri-1.8.5-3.6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:S/C:P/I:N/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.3</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20210251-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-26247.html</URL>
        <Description>CVE-2020-26247</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1180507</URL>
        <Description>SUSE Bug 1180507</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
</cvrfdoc>
