UBUNTU-CVE-2022-24836
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-24836
Summary:
Details: Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade to Nokogiri `>= 1.13.4`. There are no known workarounds for this issue.
References: https://ubuntu.com/security/CVE-2022-24836, https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-crjr-9rc5-ghw8, https://github.com/sparklemotion/nokogiri/commit/e444525ef1634b675cd1cf52d39f4320ef0aecfd, https://www.cve.org/CVERecord?id=CVE-2022-24836
Affected packages
Package
Name: ruby-nokogiri
Purl: pkg:deb/ubuntu/[email protected]+ds-1ubuntu0.1~esm1?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
