CVE-2022-24836
Summary
| CVE | CVE-2022-24836 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-11 22:15:00 UTC |
| Updated | 2023-11-07 03:44:00 UTC |
| Description | Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade to Nokogiri `>= 1.13.4`. There are no known workarounds for this issue. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 3003-1] ruby-nokogiri security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 35 Update: rubygem-nokogiri-1.13.1-2.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: rubygem-nokogiri-1.13.1-2.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Nokogiri: Multiple Vulnerabilities (GLSA 202208-29) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| About the security content of macOS Ventura 13.1 - Apple Support |
CONFIRM |
support.apple.com |
|
| [SECURITY] [DLA 3149-1] ruby-nokogiri security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 36 Update: rubygem-nokogiri-1.13.4-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: rubygem-nokogiri-1.11.7-2.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Full Disclosure: APPLE-SA-2022-12-13-4 macOS Ventura 13.1 |
FULLDISC |
seclists.org |
|
| fix(perf): HTML4::EncodingReader detection · sparklemotion/nokogiri@e444525 · GitHub |
MISC |
github.com |
|
| Inefficient Regular Expression Complexity in Nokogiri · Advisory · sparklemotion/nokogiri · GitHub |
CONFIRM |
github.com |
|
| [SECURITY] Fedora 34 Update: rubygem-nokogiri-1.11.7-2.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: rubygem-nokogiri-1.13.4-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179281 Debian Security Update for ruby-nokogiri (DLA 3003-1)
- 181134 Debian Security Update for ruby-nokogiri (DLA 3149-1)
- 182797 Debian Security Update for ruby-nokogiri (CVE-2022-24836)
- 240925 Red Hat Update for Satellite 6.12 (RHSA-2022:8506)
- 282609 Fedora Security Update for rubygem (FEDORA-2022-132c6d7c2e)
- 282610 Fedora Security Update for rubygem (FEDORA-2022-9ed7641ce0)
- 353966 Amazon Linux Security Advisory for rubygem-nokogiri, rubygem18-nokogiri : ALAS-2022-1595
- 354296 Amazon Linux Security Advisory for rubygem-nokogiri : ALAS2022-2022-062
- 355518 Amazon Linux Security Advisory for rubygem-nokogiri : AL2012-2023-417
- 377838 Apple macOS Ventura 13.1 Not Installed (HT213532)
- 502363 Alpine Linux Security Update for ruby-nokogiri
- 710597 Gentoo Linux Nokogiri Multiple Vulnerabilities (GLSA 202208-29)
- 752809 SUSE Enterprise Linux Security Update for rubygem-nokogiri (SUSE-SU-2022:4015-1)
- 752810 SUSE Enterprise Linux Security Update for rubygem-nokogiri (SUSE-SU-2022:4016-1)
- 960485 Rocky Linux Security Update for Satellite (RLSA-2022:8506)