VDB
EN
HIGH 7.5

GHSA-crjr-9rc5-ghw8

Nokogiri Inefficient Regular Expression Complexity

상세

## Summary

Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents.

## Mitigation

Upgrade to Nokogiri `>= 1.13.4`.

## Severity

The Nokogiri maintainers have evaluated this as [**High Severity** 7.5 (CVSS3.1)](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

## References

[CWE-1333](https://cwe.mitre.org/data/definitions/1333.html) Inefficient Regular Expression Complexity

## Credit

This vulnerability was reported by HackerOne user ooooooo_q (ななおく).

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

RubyGems / nokogiri
최초 영향 버전: 0 수정 버전: 1.13.4
수정 bundle update nokogiri

참고