CVE-2022-50999

Summary

Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.

Affected Software

VendorProductVersion RangeStatus
sparklemotionnokogiri0 < 1.13.5affected
sparklemotionnokogiri1.13.5unaffected

Weaknesses

  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References