CVE-2022-23516
HIGH
7,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
Description
AI Translation Available
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to stack exhaustion and raising a SystemStackError exception. This may lead to a denial of service through CPU resource consumption. This issue is patched in version 2.19.1. Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0004
Percentile
0,1th
Updated
EPSS Score Trend (Last 90 Days)
674
Uncontrolled Recursion
DraftCommon Consequences
Security Scopes Affected:
Availability
Confidentiality
Potential Impacts:
Dos: Resource Consumption (Cpu)
Dos: Resource Consumption (Memory)
Read Application Data
Applicable Platforms
All platforms may be affected
Application
Loofah by Loofah Project
Version Range Affected
From
2.2.0
(inclusive)
To
2.19.1
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:loofah_project:loofah:*:*:*:*:*:ruby:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/flavorjones/loofah/security/advisories/GHSA-3x8r-x6xp-q4vm
https://lists.debian.org/debian-lts-announce/2023/09/msg00011.html
https://lists.debian.org/debian-lts-announce/2024/09/msg00044.html
https://github.com/flavorjones/loofah/security/advisories/GHSA-3x8r-x6xp-q4vm
https://lists.debian.org/debian-lts-announce/2023/09/msg00011.html