CVE-2022-23516
Last modified
CVE-2022-23516 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to stack exhaustion and raising a SystemStackError exception. EPSS estimates a 1.10% chance of exploitation in the next 30 days.
Description
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to stack exhaustion and raising a SystemStackError exception. This may lead to a denial of service through CPU resource consumption. This issue is patched in version 2.19.1. Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Loofah Project | Loofah | >= 2.2.0, < 2.19.1 |
References
- https://github.com/flavorjones/loofah/security/advisories/GHSA-3x8r-x6xp-q4vmThird Party Advisory
- https://github.com/flavorjones/loofah/security/advisories/GHSA-3x8r-x6xp-q4vmThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-23516?
How severe is CVE-2022-23516?
How do I fix CVE-2022-23516?
Are you affected by CVE-2022-23516?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
