Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-24836

Опубликовано: 11 апр. 2022
Источник: debian
EPSS Низкий

Описание

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade to Nokogiri `>= 1.13.4`. There are no known workarounds for this issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-nokogirifixed1.13.5+dfsg-1package

Примечания

  • https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-crjr-9rc5-ghw8

  • https://github.com/sparklemotion/nokogiri/commit/e444525ef1634b675cd1cf52d39f4320ef0aecfd

EPSS

Процентиль: 77%
0.01055
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade to Nokogiri `>= 1.13.4`. There are no known workarounds for this issue.

CVSS3: 7.5
redhat
около 3 лет назад

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade to Nokogiri `>= 1.13.4`. There are no known workarounds for this issue.

CVSS3: 7.5
nvd
около 3 лет назад

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade to Nokogiri `>= 1.13.4`. There are no known workarounds for this issue.

CVSS3: 7.5
github
около 3 лет назад

Nokogiri Inefficient Regular Expression Complexity

CVSS3: 7.5
fstec
около 3 лет назад

Уязвимость программной библиотеки Nokogiri, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 77%
0.01055
Низкий