GHSL-2022-032: GHSL-2022-031_GHSL-2022-032: Type confusion in Nokogiri leads to memory leak or DoS - CVE-2022-29181
Published May 18, 2022
·Updated
Two type confusion issues while processing malicious data can be used to leak the contents of memory or cause a denial-of-service.
Affected Software
1 affected component
rubygems/nokogiri
Event History
May 18, 2022
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What conditions are required for exploitation?
An attacker needs the application to process malicious data through Nokogiri. The supplied information does not identify a required authentication level, delivery channel, or specific parser configuration.
2
Which deployments should be prioritized for review?
Prioritize applications using the rubygems/nokogiri package that process data from untrusted or attacker-influenced sources. The reported outcomes include memory-content disclosure and denial of service.
3
Can the affected or fixed version range be determined from this information?
No affected or fixed version range is provided. A Nokogiri v1.13.4 release is referenced, but the supplied data does not explicitly state that it fixes this issue or define which versions are vulnerable.