This repository has been archived by the owner on Mar 11, 2024. It is now read-only.
CVE-2022-24836 (High) detected in nokogiri-1.12.5.gem #31
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2022-24836 - High Severity Vulnerability
Vulnerable Library - nokogiri-1.12.5.gem
Nokogiri (鋸) makes it easy and painless to work with XML and HTML from Ruby. It provides a sensible, easy-to-understand API for reading, writing, modifying, and querying documents. It is fast and standards-compliant by relying on native parsers like libxml2 (C) and xerces (Java).
Library home page: https://rubygems.org/gems/nokogiri-1.12.5.gem
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri
< v1.13.4
contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade to Nokogiri>= 1.13.4
. There are no known workarounds for this issue.Publish Date: 2022-04-11
URL: CVE-2022-24836
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-crjr-9rc5-ghw8
Release Date: 2022-04-11
Fix Resolution: nokogiri - 1.13.4
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: