Uploaded image for project: 'Puppet Agent'
  1. Puppet Agent
  2. PA-4767

osx-10.15-x86_64 - NULL Pointer Dereference in nokogiri

    XMLWordPrintable

Details

    • Bug
    • Status: Resolved
    • High
    • Resolution: Done
    • None
    • puppet-agent 7.21.0
    • None
    • None
    • Phoenix
    • 1
    • Phoenix 2022-11-09, Phoenix 2022-11-23
    • Needs Assessment
    • Security Fix
    • Updates Nokogiri to 1.13.9, which addresses CVE-2022-2309, CVE-2022-40304, and CVE-2022-40303 in Nokogiri's vendored libxml2 and CVE-2022-37434 in Nokogiri's vendored zlib.
    • Needs Assessment

    Description

      nokogiri is a gem for parsing HTML, XML, SAX, and Reader.

      Affected versions of this package are vulnerable to NULL Pointer Dereference due to the usage of a vulnerable version of the bundled libxml2 package.

      More about this issue

      Vulnerability in osx-10.15-x86_64

      Introduced through: nokogiri

      CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
      CVSS Score: 7.5

      Attachments

        Issue Links

          Activity

            People

              michael.hashizume Michael Hashizume
              jira-snyk Snyk Bot
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Zendesk Support