CyberRota Analysis
AI-GeneratedNokogiri versions prior to 1.15.6 and 1.16.x before 1.16.2 are vulnerable to a critical use-after-free vulnerability in the xmlTextReader module of the packaged libxml2, which can be exploited when processing specially crafted XML documents with DTD validation and XInclude expansion enabled. This vulnerability can lead to potential application crashes or arbitrary code execution, posing significant risks to applications relying on these versions. Developers and organizations using affected Nokogiri versions should prioritize upgrading to the patched releases to mitigate these risks.
CVE
CVE-2024-58378
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Original NVD Description
Rejected reason: This CVE ID has been rejected as a duplicate.