CVE-2022-24836
published 2022-04-11CVE-2022-24836: Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `= 1.13.4`. There are no known workarounds for this issue.
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.55%
88.1th percentile
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `= 1.13.4`. There are no known workarounds for this issue.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | >= 13.0 < 13.1 | 13.1 |
| apple | macos_ventura | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ruby-nokogiri | < ruby-nokogiri 1.13.5+dfsg-1 (bookworm) | ruby-nokogiri 1.13.5+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| nokogiri | nokogiri | < 1.13.4 | 1.13.4 |
| nokogiri | nokogiri | >= 0 < 1.13.4 | 1.13.4 |
| sparklemotion | nokogiri | < 1.13.4 | 1.13.4 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-24836: Nokogiri is an open source XML and HTML library for Ruby
osv·2022-04-11·CVSS 7.5
CVE-2022-24836 [HIGH] CVE-2022-24836: Nokogiri is an open source XML and HTML library for Ruby
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `= 1.13.4`. There are no known workarounds for this issue.
OSV
Nokogiri Inefficient Regular Expression Complexity
osv·2022-04-11
CVE-2022-24836 [HIGH] Nokogiri Inefficient Regular Expression Complexity
Nokogiri Inefficient Regular Expression Complexity
## Summary
Nokogiri `= 1.13.4`.
## Severity
The Nokogiri maintainers have evaluated this as [**High Severity** 7.5 (CVSS3.1)](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
## References
[CWE-1333](https://cwe.mitre.org/data/definitions/1333.html) Inefficient Regular Expression Complexity
## Credit
This vulnerability was reported by HackerOne user ooooooo_q (ななおく).
GHSA
Nokogiri Inefficient Regular Expression Complexity
ghsa·2022-04-11
CVE-2022-24836 [HIGH] CWE-1333 Nokogiri Inefficient Regular Expression Complexity
Nokogiri Inefficient Regular Expression Complexity
## Summary
Nokogiri `= 1.13.4`.
## Severity
The Nokogiri maintainers have evaluated this as [**High Severity** 7.5 (CVSS3.1)](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
## References
[CWE-1333](https://cwe.mitre.org/data/definitions/1333.html) Inefficient Regular Expression Complexity
## Credit
This vulnerability was reported by HackerOne user ooooooo_q (ななおく).
Apple
CVE-2022-24836: macOS Ventura 13.1
vendor_apple·2022-12-13·CVSS 7.5
CVE-2022-24836 [HIGH] CVE-2022-24836: macOS Ventura 13.1
Apple Security Update: About the security content of macOS Ventura 13.1
Product: macOS Ventura
Version: 13.1
CVE: CVE-2022-24836
Component: CVE-2022-24836
Red Hat
nokogiri: ReDoS in HTML encoding detection
vendor_redhat·2022-04-11·CVSS 7.5
CVE-2022-24836 [HIGH] CWE-1333 nokogiri: ReDoS in HTML encoding detection
nokogiri: ReDoS in HTML encoding detection
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `= 1.13.4`. There are no known workarounds for this issue.
A flaw was found in the nokogiri library when processing an inefficient and complex regular expression. This flaw allows an attacker to cause excessive consumption of resources, which affects performance.
Package: rubygem-nokogiri (CloudForms Management Engine 5) - Will not fix
Package: tfm-ror51-rubygem-nokogiri (Red Hat Satellite 6) - Fix deferred
Package: tfm-ror52-rubygem-nokogiri (Red Hat Satellite 6) - Fix deferred
Debian
CVE-2022-24836: ruby-nokogiri - Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` c...
vendor_debian·2022·CVSS 7.5
CVE-2022-24836 [HIGH] CVE-2022-24836: ruby-nokogiri - Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` c...
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `= 1.13.4`. There are no known workarounds for this issue.
Scope: local
bookworm: resolved (fixed in 1.13.5+dfsg-1)
bullseye: resolved (fixed in 1.11.1+dfsg-2+deb11u1)
forky: resolved (fixed in 1.13.5+dfsg-1)
sid: resolved (fixed in 1.13.5+dfsg-1)
trixie: resolved (fixed in 1.13.5+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2022/Dec/23https://github.com/sparklemotion/nokogiri/commit/e444525ef1634b675cd1cf52d39f4320ef0aecfdhttps://github.com/sparklemotion/nokogiri/security/advisories/GHSA-crjr-9rc5-ghw8https://lists.debian.org/debian-lts-announce/2022/05/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2022/10/msg00018.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6DHCOWMA5PQTIQIMDENA7R2Y5BDYAIYM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OUPLBUZVM4WPFSXBEP2JS3R6LMKRTLFC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XMDCWRQXJQ3TFSETPCEFMQ6RR6ME5UA3/https://security.gentoo.org/glsa/202208-29https://support.apple.com/kb/HT213532http://seclists.org/fulldisclosure/2022/Dec/23https://github.com/sparklemotion/nokogiri/commit/e444525ef1634b675cd1cf52d39f4320ef0aecfdhttps://github.com/sparklemotion/nokogiri/security/advisories/GHSA-crjr-9rc5-ghw8https://lists.debian.org/debian-lts-announce/2022/05/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2022/10/msg00018.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00010.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6DHCOWMA5PQTIQIMDENA7R2Y5BDYAIYM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OUPLBUZVM4WPFSXBEP2JS3R6LMKRTLFC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XMDCWRQXJQ3TFSETPCEFMQ6RR6ME5UA3/https://security.gentoo.org/glsa/202208-29https://support.apple.com/kb/HT213532
2022-04-11
Published