Improper Handling of Unexpected Data Type Affecting nokogiri package, versions <1.13.6
Threat Intelligence
EPSS
0.37% (74th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RUBY-NOKOGIRI-2840634
- published 20 May 2022
- disclosed 19 May 2022
- credit Agustin Gianni (@agustingianni)
Introduced: 19 May 2022
CVE-2022-29181 Open this link in a new tabHow to fix?
Upgrade nokogiri
to version 1.13.6 or higher.
Overview
nokogiri is a gem for parsing HTML, XML, SAX, and Reader.
Affected versions of this package are vulnerable to Improper Handling of Unexpected Data Type due to incorrectly checking the types of arguments to various constructors in HTML4::SAX
and XML::SAX
, which causes a segmentation fault.
References
CVSS Scores
version 3.1