Описание
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri < v1.13.4
contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade to Nokogiri >= 1.13.4
. There are no known workarounds for this issue.
A flaw was found in the nokogiri library when processing an inefficient and complex regular expression. This flaw allows an attacker to cause excessive consumption of resources, which affects performance.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
CloudForms Management Engine 5 | rubygem-nokogiri | Will not fix | ||
Red Hat Satellite 6 | tfm-ror51-rubygem-nokogiri | Fix deferred | ||
Red Hat Satellite 6 | tfm-ror52-rubygem-nokogiri | Fix deferred | ||
Red Hat Satellite 6.12 for RHEL 8 | rubygem-nokogiri | Fixed | RHSA-2022:8506 | 16.11.2022 |
Red Hat Satellite 6.12 for RHEL 8 | rubygem-nokogiri | Fixed | RHSA-2022:8506 | 16.11.2022 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade to Nokogiri `>= 1.13.4`. There are no known workarounds for this issue.
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade to Nokogiri `>= 1.13.4`. There are no known workarounds for this issue.
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< ...
Nokogiri Inefficient Regular Expression Complexity
Уязвимость программной библиотеки Nokogiri, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
7.5 High
CVSS3