VDB
KO
HIGH 8.8

GHSA-59gp-qqm7-cw4j

Nokogiri has vulnerable dependencies on libxml2 and libxslt

Details

Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems / nokogiri
Introduced in: 0 Fixed in: 1.13.2
Fix bundle update nokogiri

References