CVE-2022-24839
Summary
| CVE | CVE-2022-24839 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-11 22:15:00 UTC |
| Updated | 2023-02-23 20:19:00 UTC |
| Description | org.cyberneko.html is an html parser written in Java. The fork of `org.cyberneko.html` used by Nokogiri (Rubygem) raises a `java.lang.OutOfMemoryError` exception when parsing ill-formed HTML markup. Users are advised to upgrade to `>= 1.9.22.noko2`. Note: The upstream library `org.cyberneko.html` is no longer maintained. Nokogiri uses its own fork of this library located at https://github.com/sparklemotion/nekohtml and this CVE applies only to that fork. Other forks of nekohtml may have a similar vulnerability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Uncontrolled Resource Consumption in org.cyberneko.html (nokogiri fork) · Advisory · sparklemotion/nekohtml · GitHub |
CONFIRM |
github.com |
|
| fix: ensure ill-formed PIs are parsed correctly · sparklemotion/nekohtml@a800fce · GitHub |
MISC |
github.com |
|
| Oracle Critical Patch Update Advisory - July 2022 |
N/A |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182010 Debian Security Update for nekohtml (CVE-2022-24839)
- 378357 IBM WebSphere Application Server Liberty Denial of Service (DoS) Vulnerability (6824871)
- 379158 Atlassian Jira Service Management Data Center and Server Third-Party Dependency Vulnerability (JSDSERVER-14921)
- 379516 IBM Sterling Secure Proxy Multiple Vulnerabilities (7142038)
- 730976 Atlassian Confluence Data Center and Server Denial of Service (DoS) Vulnerability (CONFSERVER-93169)
- 731316 Atlassian Jira Software Data Center and Server Denial of Service (DoS) Vulnerability (JSWSERVER-25842)