Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459
Low severity
GitHub Reviewed
Published
May 13, 2024
in
sparklemotion/nokogiri
•
Updated May 16, 2024
Description
Published to the GitHub Advisory Database
May 13, 2024
Reviewed
May 13, 2024
Last updated
May 16, 2024
Summary
Nokogiri v1.16.5 upgrades its dependency libxml2 to 2.12.7 from 2.12.6.
libxml2 v2.12.7 addresses CVE-2024-34459:
Impact
There is no impact to Nokogiri users because the issue is present only in libxml2's
xmllint
tool which Nokogiri does not provide or expose.Timeline
References