CVE-2022-23308: Use After Free
(updated )
valid.c
in libxml2 before 2.9.13 has a use-after-free of ID
and IDREF
attributes, which is vendored in Nokogiri before 1.13.2.
References
Detect and mitigate CVE-2022-23308 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →