CVE-2022-29181
Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated memory.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated memory. Version 1.13.6 contains a patch for this issue. As a workaround, ensure the untrusted input is a `String` by calling `#to_s` or equivalent.
- CVSS 3.1
- 8.2 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
- EPSS
- 3.23% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-241, CWE-843
- Affected
- nokogiri/nokogiri · apple/macos
- Source
- security-advisories@github.com
References
- https://github.com/sparklemotion/nokogiri/commit/83cc451c3f29df397caa890afc3b714eae6ab8f7
- https://github.com/sparklemotion/nokogiri/commit/db05ba9a1bd4b90aa6c76742cf6102a7c7297267Patch, Third Party Advisory
- https://github.com/sparklemotion/nokogiri/releases/tag/v1.13.6Release Notes, Third Party Advisory
- https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-xh29-r2w5-wx8mIssue Tracking, Third Party Advisory
- https://securitylab.github.com/advisories/GHSL-2022-031_GHSL-2022-032_Nokogiri
- http://seclists.org/fulldisclosure/2022/Dec/23Mailing List, Third Party Advisory
- https://github.com/sparklemotion/nokogiri/commit/db05ba9a1bd4b90aa6c76742cf6102a7c7297267Patch, Third Party Advisory
- https://github.com/sparklemotion/nokogiri/releases/tag/v1.13.6Release Notes, Third Party Advisory
- https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-xh29-r2w5-wx8mIssue Tracking, Third Party Advisory
- https://security.gentoo.org/glsa/202208-29Third Party Advisory
- https://securitylab.github.com/advisories/GHSL-2022-031_GHSL-2022-032_Nokogiri/Exploit, Third Party Advisory
- https://support.apple.com/kb/HT213532Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.