Lucene search

K
cvelistGitHub_MCVELIST:CVE-2022-24839
HistoryApr 11, 2022 - 9:25 p.m.

CVE-2022-24839 Uncontrolled Resource Consumption in org.cyberneko.html (nokogiri fork)

2022-04-1121:25:12
CWE-400
GitHub_M
www.cve.org
10
cve-2022-24839
uncontrolled resource consumption
org.cyberneko.html
nokogiri
outofmemoryerror
java
ill-formed html markup
upgrade
nekohtml
vulnerability

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

57.1%

org.cyberneko.html is an html parser written in Java. The fork of org.cyberneko.html used by Nokogiri (Rubygem) raises a java.lang.OutOfMemoryError exception when parsing ill-formed HTML markup. Users are advised to upgrade to >= 1.9.22.noko2. Note: The upstream library org.cyberneko.html is no longer maintained. Nokogiri uses its own fork of this library located at https://github.com/sparklemotion/nekohtml and this CVE applies only to that fork. Other forks of nekohtml may have a similar vulnerability.

CNA Affected

[
  {
    "product": "nekohtml",
    "vendor": "sparklemotion",
    "versions": [
      {
        "status": "affected",
        "version": "< 1.9.22.noko2"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

57.1%