VDB
KO
HIGH 8.8

GHSA-v4f8-2847-rwm7

Nokogiri Implements libxml2 version vulnerable to use-after-free

Details

There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems / nokogiri
Introduced in: 0 Fixed in: 1.11.4
Fix bundle update nokogiri

References