Authors: Created by IBM


There is a vulnerability in the Neko HTML library used by IBM WebSphere Application Server Liberty with the openid-2.0 feature enabled.This has been addressed. CVEID:  CVE-2022-24839[1]
DESCRIPTION:  Sparkle Motion Nokogiri is vulnerable to a denial of service, caused by a java.lang.OutOfMemoryError exception when parsing ill-formed HTML markup in the fork of org.cyberneko.html.By sending a specially-crafted request, a remote attacker could exploit this vulnerability to...

Just published by IBM: Read more