Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-crjr-9rc5-ghw8

Опубликовано: 11 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Nokogiri Inefficient Regular Expression Complexity

Summary

Nokogiri < v1.13.4 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents.

Mitigation

Upgrade to Nokogiri >= 1.13.4.

Severity

The Nokogiri maintainers have evaluated this as High Severity 7.5 (CVSS3.1).

References

CWE-1333 Inefficient Regular Expression Complexity

Credit

This vulnerability was reported by HackerOne user ooooooo_q (ななおく).

Пакеты

Наименование

nokogiri

rubygems
Затронутые версииВерсия исправления

< 1.13.4

1.13.4

EPSS

Процентиль: 77%
0.01055
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333
CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade to Nokogiri `>= 1.13.4`. There are no known workarounds for this issue.

CVSS3: 7.5
redhat
около 3 лет назад

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade to Nokogiri `>= 1.13.4`. There are no known workarounds for this issue.

CVSS3: 7.5
nvd
около 3 лет назад

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade to Nokogiri `>= 1.13.4`. There are no known workarounds for this issue.

CVSS3: 7.5
debian
около 3 лет назад

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< ...

CVSS3: 7.5
fstec
около 3 лет назад

Уязвимость программной библиотеки Nokogiri, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 77%
0.01055
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333
CWE-400