Miggo Logo

GHSA-r3w4-36x6-7r99: Duplicate Advisory: Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459

N/A

CVSS Score

Basic Information

CVE ID
-
EPSS Score
-
Published
5/14/2024
Updated
5/16/2024
KEV Status
No
Technology
TechnologyRuby

Technical Details

CVSS Vector
-
Package NameEcosystemVulnerable VersionsFirst Patched Version
nokogirirubygems< 1.16.51.16.5

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The vulnerability CVE-2024-34459 resides in libxml2's xmllint tool, specifically in its command-line argument handling. However, Nokogiri does not include or expose the xmllint tool in its codebase or functionality. The advisory explicitly states there is no impact to Nokogiri users because the vulnerable component (xmllint) is not part of Nokogiri's provided features. While libxml2 itself is a dependency, the specific vulnerable functions related to this CVE are isolated to xmllint, which Nokogiri does not utilize. Therefore, no vulnerable functions within Nokogiri's codebase or its exposed dependencies are identified for this specific issue.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

## *upli**t* **visory T*is **visory **s ***n wit**r*wn ****us* it is * *upli**t* o* **S*-r***-*x**-r***. T*is link is m*int*in** to pr*s*rv* *xt*rn*l r***r*n**s. ## Ori*in*l **s*ription ## Summ*ry Noko*iri v*.**.* up*r***s its **p*n**n*y li*xml*

Reasoning

T** vuln*r**ility *V*-****-***** r*si**s in li*xml*'s `xmllint` tool, sp**i*i**lly in its *omm*n*-lin* *r*um*nt **n*lin*. *ow*v*r, Noko*iri *o*s not in*lu** or *xpos* t** `xmllint` tool in its *o****s* or *un*tion*lity. T** **visory *xpli*itly st*t*s