Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g9hh-vvx3-v37v

Опубликовано: 23 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Denial of service in HtmlUnit-Neko

Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit-Neko through 2.26, and is fixed in 2.27. This issue also exists in CyberNeko HTML through 1.9.22 (also affecting OWASP AntiSamy before 1.6.6), but 1.9.22 is the last version of CyberNeko HTML. NOTE: this may be related to CVE-2022-24939.

Пакеты

Наименование

net.sourceforge.htmlunit:neko-htmlunit

maven
Затронутые версииВерсия исправления

< 2.27

2.27

EPSS

Процентиль: 40%
0.00179
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit-Neko through 2.26, and is fixed in 2.27. This issue also exists in CyberNeko HTML through 1.9.22 (also affecting OWASP AntiSamy before 1.6.6), but 1.9.22 is the last version of CyberNeko HTML. NOTE: this may be related to CVE-2022-24839.

CVSS3: 7.5
nvd
почти 4 года назад

Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit-Neko through 2.26, and is fixed in 2.27. This issue also exists in CyberNeko HTML through 1.9.22 (also affecting OWASP AntiSamy before 1.6.6), but 1.9.22 is the last version of CyberNeko HTML. NOTE: this may be related to CVE-2022-24839.

CVSS3: 7.5
debian
почти 4 года назад

Certain Neko-related HTML parsers allow a denial of service via crafte ...

EPSS

Процентиль: 40%
0.00179
Низкий

7.5 High

CVSS3