Oval Definition:oval:org.opensuse.security:def:202223514
Revision Date:2023-06-22Version:1
Title:CVE-2022-23514
Description:

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption. This issue is patched in version 2.19.1.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2022-23514
SUSE CVE-2022-23514
SUSE-SU-2023:1657-1
Platform(s):SUSE Linux Enterprise High Availability Extension 15 SP5
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise High Availability Extension 15 SP5 is installed
  • AND ruby2.5-rubygem-loofah is affected
  • BACK