saif-khan1211 / First_real_scan

Apache License 2.0
0 stars 1 forks source link

CVE-2022-29546 (High) detected in nekohtml-1.9.19.jar #320

Open mend-bolt-for-github[bot] opened 8 months ago

mend-bolt-for-github[bot] commented 8 months ago

CVE-2022-29546 - High Severity Vulnerability

Vulnerable Library - nekohtml-1.9.19.jar

An HTML parser and tag balancer.

Library home page: http://nekohtml.sourceforge.net/

Path to vulnerable library: /target/libs/provided/nekohtml-1.9.19.jar

Dependency Hierarchy: - :x: **nekohtml-1.9.19.jar** (Vulnerable Library)

Found in HEAD commit: 517ce877d9ca28b78d99878eae6078eb4dbd1e1b

Found in base branch: main

Vulnerability Details

HtmlUnit NekoHtml Parser before 2.61.0 suffers from a denial of service vulnerability. Crafted input associated with the parsing of Processing Instruction (PI) data leads to heap memory consumption. This is similar to CVE-2022-28366 but affects a much later version of the product.

Publish Date: 2022-04-25

URL: CVE-2022-29546

CVSS 3 Score Details (7.5)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: None - Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2022-04-25

Fix Resolution: net.sourceforge.htmlunit:neko-htmlunit:2.61.0


Step up your Open Source Security Game with Mend here