{
  "threat_severity" : "Important",
  "public_date" : "2022-04-11T00:00:00Z",
  "bugzilla" : {
    "description" : "nokogiri: ReDoS in HTML encoding detection",
    "id" : "2074346",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2074346"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-1333",
  "details" : [ "Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade to Nokogiri `>= 1.13.4`. There are no known workarounds for this issue.", "A flaw was found in the nokogiri library when processing an inefficient and complex regular expression. This flaw allows an attacker to cause excessive consumption of resources, which affects performance." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Satellite 6.12 for RHEL 8",
    "release_date" : "2022-11-16T00:00:00Z",
    "advisory" : "RHSA-2022:8506",
    "cpe" : "cpe:/a:redhat:satellite:6.12::el8",
    "package" : "tfm-rubygem-nokogiri-0:1.13.8-1.el8sat",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat Satellite 6.12 for RHEL 8",
    "release_date" : "2022-11-16T00:00:00Z",
    "advisory" : "RHSA-2022:8506",
    "cpe" : "cpe:/a:redhat:satellite_capsule:6.12::el8",
    "package" : "tfm-rubygem-nokogiri-0:1.13.8-1.el8sat",
    "impact" : "low"
  } ],
  "package_state" : [ {
    "product_name" : "CloudForms Management Engine 5",
    "fix_state" : "Will not fix",
    "package_name" : "rubygem-nokogiri",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5"
  }, {
    "product_name" : "Red Hat Satellite 6",
    "fix_state" : "Fix deferred",
    "package_name" : "tfm-ror51-rubygem-nokogiri",
    "cpe" : "cpe:/a:redhat:satellite:6",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat Satellite 6",
    "fix_state" : "Fix deferred",
    "package_name" : "tfm-ror52-rubygem-nokogiri",
    "cpe" : "cpe:/a:redhat:satellite:6",
    "impact" : "low"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2022-24836\nhttps://nvd.nist.gov/vuln/detail/CVE-2022-24836\nhttps://github.com/sparklemotion/nokogiri/security/advisories/GHSA-crjr-9rc5-ghw8" ],
  "name" : "CVE-2022-24836",
  "csaw" : false
}