Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-28366
HistoryApr 21, 2022 - 12:00 a.m.

CVE-2022-28366

2022-04-2100:00:00
ubuntu.com
ubuntu.com
20
neko-related html
denial of service
crafted input
memory consumption
htmlunit-neko
cyberneko html
cve-2022-28366

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

57.1%

Certain Neko-related HTML parsers allow a denial of service via crafted
Processing Instruction (PI) input that causes excessive heap memory
consumption. In particular, this issue exists in HtmlUnit-Neko through
2.26, and is fixed in 2.27. This issue also exists in CyberNeko HTML
through 1.9.22 (also affecting OWASP AntiSamy before 1.6.6), but 1.9.22 is
the last version of CyberNeko HTML. NOTE: this may be related to
CVE-2022-24839.

Bugs

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

57.1%