This repository has been archived by the owner on Nov 2, 2022. It is now read-only.
CVE-2022-24839 (High) detected in nekohtml-1.9.14.jar #241
Labels
security vulnerability
Security vulnerability detected by WhiteSource
CVE-2022-24839 - High Severity Vulnerability
Vulnerable Library - nekohtml-1.9.14.jar
Library home page: http://nekohtml.sourceforge.net/
Path to dependency file: /modules/cucumber/modules/cucumber4oas/pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/net/sourceforge/nekohtml/nekohtml/1.9.14/nekohtml-1.9.14.jar,/home/wss-scanner/.m2/repository/net/sourceforge/nekohtml/nekohtml/1.9.14/nekohtml-1.9.14.jar,/home/wss-scanner/.m2/repository/net/sourceforge/nekohtml/nekohtml/1.9.14/nekohtml-1.9.14.jar,/home/wss-scanner/.m2/repository/net/sourceforge/nekohtml/nekohtml/1.9.14/nekohtml-1.9.14.jar,/home/wss-scanner/.m2/repository/net/sourceforge/nekohtml/nekohtml/1.9.14/nekohtml-1.9.14.jar,/home/wss-scanner/.m2/repository/net/sourceforge/nekohtml/nekohtml/1.9.14/nekohtml-1.9.14.jar,/home/wss-scanner/.m2/repository/net/sourceforge/nekohtml/nekohtml/1.9.14/nekohtml-1.9.14.jar,/home/wss-scanner/.m2/repository/net/sourceforge/nekohtml/nekohtml/1.9.14/nekohtml-1.9.14.jar,/home/wss-scanner/.m2/repository/net/sourceforge/nekohtml/nekohtml/1.9.14/nekohtml-1.9.14.jar,/home/wss-scanner/.m2/repository/net/sourceforge/nekohtml/nekohtml/1.9.14/nekohtml-1.9.14.jar
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
org.cyberneko.html is an html parser written in Java. The fork of
org.cyberneko.html
used by Nokogiri (Rubygem) raises ajava.lang.OutOfMemoryError
exception when parsing ill-formed HTML markup. Users are advised to upgrade to>= 1.9.22.noko2
. Note: The upstream libraryorg.cyberneko.html
is no longer maintained. Nokogiri uses its own fork of this library located at https://github.com/sparklemotion/nekohtml and this CVE applies only to that fork. Other forks of nekohtml may have a similar vulnerability.Publish Date: 2022-04-11
URL: CVE-2022-24839
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-9849-p7jc-9rmv
Release Date: 2022-04-11
Fix Resolution: net.sourceforge.nekohtml:nekohtml:1.9.22.noko2
The text was updated successfully, but these errors were encountered: