Nokogiri Implements libxml2 version vulnerable to use-after-free
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jul 19, 2023
Description
Published by the National Vulnerability Database
May 18, 2021
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jul 5, 2023
Last updated
Jul 19, 2023
There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.
References