Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-486f-hjj9-9vhh

Опубликовано: 13 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Inefficient Regular Expression Complexity in Loofah

Summary

Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption.

Mitigation

Upgrade to Loofah >= 2.19.1.

Severity

The Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1).

References

Credit

This vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q).

Пакеты

Наименование

loofah

rubygems
Затронутые версииВерсия исправления

< 2.19.1

2.19.1

EPSS

Процентиль: 52%
0.00293
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption. This issue is patched in version 2.19.1.

CVSS3: 7.5
redhat
около 3 лет назад

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption. This issue is patched in version 2.19.1.

CVSS3: 7.5
nvd
около 3 лет назад

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption. This issue is patched in version 2.19.1.

CVSS3: 7.5
debian
около 3 лет назад

Loofah is a general library for manipulating and transforming HTML/XML ...

suse-cvrf
почти 3 года назад

Security update for rubygem-loofah

EPSS

Процентиль: 52%
0.00293
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333