VDB
BDU%3A2024-02313
BDU%3A2024-02313
PUBLISHED
CVSS 8.5 HIGH
Уязвимость программной библиотеки Nokogiri интерпретатора Ruby, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
8.5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Сообщество свободного программного обеспечения, Red Hat Inc., ООО «Ред Софт», Elastic NV, Apple Inc. | SUSE OpenStack Cloud Crowbar, Debian GNU/Linux, openSUSE Tumbleweed, CloudForms Management Engine, SUSE Linux Enterprise Module for Basesystem, OpenSUSE Leap, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Linux Enterprise High Performance Computing, Suse Linux Enterprise Server, SUSE Manager Proxy, SUSE Manager Server, Suse Linux Enterprise Desktop, SUSE Manager Retail Branch Server, SUSE Enterprise Storage, SUSE Linux Enterprise High Availability Extension, Red Hat Satellite, Logstash, MacOS, Nokogiri |
Timeline
- Mar 26, 2024 CVE Published
- Sep 8, 2025 CVE Updated
References
- http://seclists.org/fulldisclosure/2022/Dec/23 url
- https://github.com/sparklemotion/nokogiri/commit/db05ba9a1bd4b90aa6c76742cf6102a7c7297267 url
- https://github.com/sparklemotion/nokogiri/releases/tag/v1.13.6 url
- https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-xh29-r2w5-wx8m url
- https://security.gentoo.org/glsa/202208-29 url
- https://securitylab.github.com/advisories/GHSL-2022-031_GHSL-2022-032_Nokogiri/ url
- https://support.apple.com/kb/HT213532 url
- https://www.suse.com/security/cve/CVE-2022-29181.html url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://security-tracker.debian.org/tracker/CVE-2022-29181 advisory
- https://access.redhat.com/security/cve/CVE-2022-29181 advisory
- https://support.apple.com/ru-ru/HT213532 advisory