Логотип exploitDog
bind:CVE-2022-23516
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-23516

Количество 6

Количество 6

ubuntu логотип

CVE-2022-23516

около 3 лет назад

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to stack exhaustion and raising a SystemStackError exception. This may lead to a denial of service through CPU resource consumption. This issue is patched in version 2.19.1. Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-23516

около 3 лет назад

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to stack exhaustion and raising a SystemStackError exception. This may lead to a denial of service through CPU resource consumption. This issue is patched in version 2.19.1. Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-23516

около 3 лет назад

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to stack exhaustion and raising a SystemStackError exception. This may lead to a denial of service through CPU resource consumption. This issue is patched in version 2.19.1. Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-23516

около 3 лет назад

Loofah is a general library for manipulating and transforming HTML/XML ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3x8r-x6xp-q4vm

около 3 лет назад

Uncontrolled Recursion in Loofah

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1657-1

почти 3 года назад

Security update for rubygem-loofah

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-23516

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to stack exhaustion and raising a SystemStackError exception. This may lead to a denial of service through CPU resource consumption. This issue is patched in version 2.19.1. Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-23516

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to stack exhaustion and raising a SystemStackError exception. This may lead to a denial of service through CPU resource consumption. This issue is patched in version 2.19.1. Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-23516

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to stack exhaustion and raising a SystemStackError exception. This may lead to a denial of service through CPU resource consumption. This issue is patched in version 2.19.1. Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-23516

Loofah is a general library for manipulating and transforming HTML/XML ...

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-3x8r-x6xp-q4vm

Uncontrolled Recursion in Loofah

CVSS3: 7.5
0%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:1657-1

Security update for rubygem-loofah

почти 3 года назад

Уязвимостей на страницу