ID

VAR-202205-1646


CVE

CVE-2022-29181


TITLE

Nokogiri  Vulnerability regarding mix-ups in

Trust: 0.8

sources: JVNDB: JVNDB-2022-011583

DESCRIPTION

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated memory. Version 1.13.6 contains a patch for this issue. As a workaround, ensure the untrusted input is a `String` by calling `#to_s` or equivalent. Nokogiri contains a type confusion vulnerability.Information is obtained and service operation is interrupted (DoS) It may be in a state. Nokogiri versions 1.13.6-1.1 and later have a security vulnerability that could be exploited by an attacker to trigger Nokogiri's memory corruption, triggering a denial of service and potentially running code. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202208-29 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: Nokogiri: Multiple Vulnerabilities Date: August 14, 2022 Bugs: #846623, #837902, #762685 ID: 202208-29 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been discovered in Nokogiri, the worst of which could result in denial of service. Background ========= Nokogiri is an HTML, XML, SAX, and Reader parser. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-ruby/nokogiri < 1.13.6 >= 1.13.6 Description ========== Multiple vulnerabilities have been discovered in Nokogiri. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Nokogiri users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">\xdev-ruby/nokogiri-1.13.6" References ========= [ 1 ] CVE-2020-26247 https://nvd.nist.gov/vuln/detail/CVE-2020-26247 [ 2 ] CVE-2022-24836 https://nvd.nist.gov/vuln/detail/CVE-2022-24836 [ 3 ] CVE-2022-29181 https://nvd.nist.gov/vuln/detail/CVE-2022-29181 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202208-29 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2022 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2022-12-13-4 macOS Ventura 13.1 macOS Ventura 13.1 addresses the following issues. Information about the security content is also available at https://support.apple.com/HT213532. Accounts Available for: macOS Ventura Impact: A user may be able to view sensitive user information Description: This issue was addressed with improved data protection. CVE-2022-42843: Mickey Jin (@patch1t) AMD Available for: macOS Ventura Impact: An app may be able to execute arbitrary code with kernel privileges Description: An out-of-bounds write issue was addressed with improved input validation. CVE-2022-42847: ABC Research s.r.o. AppleMobileFileIntegrity Available for: macOS Ventura Impact: An app may be able to bypass Privacy preferences Description: This issue was addressed by enabling hardened runtime. CVE-2022-42865: Wojciech Reguła (@_r3ggi) of SecuRing Bluetooth Available for: macOS Ventura Impact: An app may be able to disclose kernel memory Description: The issue was addressed with improved memory handling. CVE-2022-42854: Pan ZhenPeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. (@starlabs_sg) Boot Camp Available for: macOS Ventura Impact: An app may be able to modify protected parts of the file system Description: An access issue was addressed with improved access restrictions. CVE-2022-42853: Mickey Jin (@patch1t) of Trend Micro CoreServices Available for: macOS Ventura Impact: An app may be able to bypass Privacy preferences Description: Multiple issues were addressed by removing the vulnerable code. CVE-2022-42859: Mickey Jin (@patch1t), Csaba Fitzl (@theevilbit) of Offensive Security DriverKit Available for: macOS Ventura Impact: An app may be able to execute arbitrary code with kernel privileges Description: The issue was addressed with improved memory handling. CVE-2022-32942: Linus Henze of Pinauten GmbH (pinauten.de) ImageIO Available for: macOS Ventura Impact: Processing a maliciously crafted file may lead to arbitrary code execution Description: An out-of-bounds write issue was addressed with improved input validation. CVE-2022-46693: Mickey Jin (@patch1t) IOHIDFamily Available for: macOS Ventura Impact: An app may be able to execute arbitrary code with kernel privileges Description: A race condition was addressed with improved state handling. CVE-2022-42864: Tommy Muir (@Muirey03) IOMobileFrameBuffer Available for: macOS Ventura Impact: An app may be able to execute arbitrary code with kernel privileges Description: An out-of-bounds write issue was addressed with improved input validation. CVE-2022-46690: John Aakerblom (@jaakerblom) IOMobileFrameBuffer Available for: macOS Ventura Impact: An app may be able to execute arbitrary code with kernel privileges Description: An out-of-bounds access issue was addressed with improved bounds checking. CVE-2022-46697: John Aakerblom (@jaakerblom) and Antonio Zekic (@antoniozekic) iTunes Store Available for: macOS Ventura Impact: A remote user may be able to cause unexpected app termination or arbitrary code execution Description: An issue existed in the parsing of URLs. This issue was addressed with improved input validation. CVE-2022-42837: Weijia Dai (@dwj1210) of Momo Security Kernel Available for: macOS Ventura Impact: An app may be able to execute arbitrary code with kernel privileges Description: A race condition was addressed with additional validation. CVE-2022-46689: Ian Beer of Google Project Zero Kernel Available for: macOS Ventura Impact: Connecting to a malicious NFS server may lead to arbitrary code execution with kernel privileges Description: The issue was addressed with improved bounds checks. CVE-2022-46701: Felix Poulin-Belanger Kernel Available for: macOS Ventura Impact: A remote user may be able to cause kernel code execution Description: The issue was addressed with improved memory handling. CVE-2022-42842: pattern-f (@pattern_F_) of Ant Security Light-Year Lab Kernel Available for: macOS Ventura Impact: An app may be able to break out of its sandbox Description: This issue was addressed with improved checks. CVE-2022-42861: pattern-f (@pattern_F_) of Ant Security Light-Year Lab Kernel Available for: macOS Ventura Impact: An app with root privileges may be able to execute arbitrary code with kernel privileges Description: The issue was addressed with improved memory handling. CVE-2022-42845: Adam Doupé of ASU SEFCOM Photos Available for: macOS Ventura Impact: Shake-to-undo may allow a deleted photo to be re-surfaced without authentication Description: The issue was addressed with improved bounds checks. CVE-2022-32943: an anonymous researcher ppp Available for: macOS Ventura Impact: An app may be able to execute arbitrary code with kernel privileges Description: The issue was addressed with improved memory handling. CVE-2022-42840: an anonymous researcher Preferences Available for: macOS Ventura Impact: An app may be able to use arbitrary entitlements Description: A logic issue was addressed with improved state management. CVE-2022-42855: Ivan Fratric of Google Project Zero Printing Available for: macOS Ventura Impact: An app may be able to bypass Privacy preferences Description: This issue was addressed by removing the vulnerable code. CVE-2022-42862: Mickey Jin (@patch1t) Ruby Available for: macOS Ventura Impact: A remote user may be able to cause unexpected app termination or arbitrary code execution Description: This issue was addressed with improved checks. CVE-2022-24836 CVE-2022-29181 Safari Available for: macOS Ventura Impact: Visiting a website that frames malicious content may lead to UI spoofing Description: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. CVE-2022-46695: KirtiKumar Anandrao Ramchandani Weather Available for: macOS Ventura Impact: An app may be able to read sensitive location information Description: The issue was addressed with improved handling of caches. CVE-2022-42866: an anonymous researcher WebKit Available for: macOS Ventura Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: A use after free issue was addressed with improved memory management. WebKit Bugzilla: 245521 CVE-2022-42867: Maddie Stone of Google Project Zero WebKit Available for: macOS Ventura Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: A memory consumption issue was addressed with improved memory handling. WebKit Bugzilla: 245466 CVE-2022-46691: an anonymous researcher WebKit Available for: macOS Ventura Impact: Processing maliciously crafted web content may bypass Same Origin Policy Description: A logic issue was addressed with improved state management. WebKit Bugzilla: 246783 CVE-2022-46692: KirtiKumar Anandrao Ramchandani WebKit Available for: macOS Ventura Impact: Processing maliciously crafted web content may result in the disclosure of process memory Description: The issue was addressed with improved memory handling. CVE-2022-42852: hazbinhotel working with Trend Micro Zero Day Initiative WebKit Available for: macOS Ventura Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: A memory corruption issue was addressed with improved input validation. WebKit Bugzilla: 246942 CVE-2022-46696: Samuel Groß of Google V8 Security WebKit Bugzilla: 247562 CVE-2022-46700: Samuel Groß of Google V8 Security WebKit Available for: macOS Ventura Impact: Processing maliciously crafted web content may disclose sensitive user information Description: A logic issue was addressed with improved checks. CVE-2022-46698: Dohyun Lee (@l33d0hyun) of SSD Secure Disclosure Labs & DNSLab, Korea Univ. WebKit Available for: macOS Ventura Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: A memory corruption issue was addressed with improved state management. WebKit Bugzilla: 247420 CVE-2022-46699: Samuel Groß of Google V8 Security WebKit Bugzilla: 244622 CVE-2022-42863: an anonymous researcher WebKit Available for: macOS Ventura Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1. WebKit Bugzilla: 248266 CVE-2022-42856: Clément Lecigne of Google's Threat Analysis Group xar Available for: macOS Ventura Impact: Processing a maliciously crafted package may lead to arbitrary code execution Description: A type confusion issue was addressed with improved checks. CVE-2022-42841: Thijs Alkemade (@xnyhps) of Computest Sector 7 Additional recognition Kernel We would like to acknowledge Zweig of Kunlun Lab for their assistance. Lock Screen We would like to acknowledge Kevin Mann for their assistance. Safari Extensions We would like to acknowledge Oliver Dunk and Christian R. of 1Password for their assistance. WebKit We would like to acknowledge an anonymous researcher and scarlet for their assistance. macOS Ventura 13.1 may be obtained from the Mac App Store or Apple's Software Downloads web site: https://support.apple.com/downloads/ All information is also posted on the Apple Security Updates web site: https://support.apple.com/en-us/HT201222. This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEBP+4DupqR5Sgt1DB4RjMIDkeNxkFAmOZFYAACgkQ4RjMIDke Nxk1zRAAuqDsK19ODzl+oIO6xYMDcbiQV/ibvU9uwLtwTR8Y2wLga9V/vaaPTS6z qRkTivKEfdLMVW8Xlzl1jb+BMS0+dIjYrPAFatU8A5H2A3MLY5Trl9tTs+D8BgQJ reLRAyR6qJVwu+VMMjgrUxkQliPNYeumrmLwmKJdByYPzv4GLY5bOIf6siUAIJdB vs2zzcq6+BnoJkS1iYa+Ub5S3bSryR2i8vrSit6PcYBtLKHxUJaK2YBdA8LoqB4J wenkEaEhyilm0bpyyF0VxDuvOcotqrGa2ikScrik/N/NueMqDi9duo9kKKVia0xa Gx2cYLNDG10KBmz9w9B8YC6lNa6t7M5zmCYn8TmXTfndd7fCYbYajZNT0WxIYteK sXYPkVpqEd4KVZxtQ3MfHlx5y4FwnqBkLACnfsNCs4KatbJPEg9Qy9Mn2ymi/9He UoVt3XnQVhAgGIRV2qezjV9r0rtgnWpSKvFd9LSDcB9F6b/bzRipbxVnqdWCL1If ymeeEY8BJ7WJnFqgXzRo42+4bp4R67iNH+Z/JjUy/Z7C3f2O66fFZu2pNL1vLILA Wi/dprF13SjqCIavwWPbVL8UvfaAwBz53y38gwei6eSdsEO383r0XIIKjErGbWm6 hqHq/QKTWHQZqUFj4kUb4Ajw8Qe0j0qSrCLt4Wl11u/0r5hTRyI= =C5EK -----END PGP SIGNATURE-----

Trust: 1.98

sources: NVD: CVE-2022-29181 // JVNDB: JVNDB-2022-011583 // VULHUB: VHN-420715 // VULMON: CVE-2022-29181 // PACKETSTORM: 168080 // PACKETSTORM: 170314

AFFECTED PRODUCTS

vendor:applemodel:macosscope:gteversion:13.0

Trust: 1.0

vendor:nokogirimodel:nokogiriscope:ltversion:1.13.6

Trust: 1.0

vendor:applemodel:macosscope:ltversion:13.1

Trust: 1.0

vendor:nokogirimodel:nokogiriscope: - version: -

Trust: 0.8

vendor:アップルmodel:macosscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-011583 // NVD: CVE-2022-29181

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-29181
value: HIGH

Trust: 1.0

security-advisories@github.com: CVE-2022-29181
value: HIGH

Trust: 1.0

NVD: CVE-2022-29181
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202205-3804
value: HIGH

Trust: 0.6

VULHUB: VHN-420715
value: MEDIUM

Trust: 0.1

VULMON: CVE-2022-29181
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2022-29181
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-420715
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2022-29181
baseSeverity: HIGH
baseScore: 8.2
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 4.2
version: 3.1

Trust: 2.0

OTHER: JVNDB-2022-011583
baseSeverity: HIGH
baseScore: 8.2
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-420715 // VULMON: CVE-2022-29181 // JVNDB: JVNDB-2022-011583 // CNNVD: CNNVD-202205-3804 // NVD: CVE-2022-29181 // NVD: CVE-2022-29181

PROBLEMTYPE DATA

problemtype:CWE-241

Trust: 1.1

problemtype:CWE-843

Trust: 1.0

problemtype:Mistake of type (CWE-843) [NVD evaluation ]

Trust: 0.8

sources: VULHUB: VHN-420715 // JVNDB: JVNDB-2022-011583 // NVD: CVE-2022-29181

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202205-3804

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202205-3804

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-420715

PATCH

title:HT213532 Apple  Security updateurl:https://github.com/sparklemotion/nokogiri/commit/db05ba9a1bd4b90aa6c76742cf6102a7c7297267

Trust: 0.8

title:Nokogiri Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=193839

Trust: 0.6

title:Amazon Linux AMI: ALAS-2022-1648url:https://vulmon.com/vendoradvisory?qidtp=amazon_linux_ami&qid=ALAS-2022-1648

Trust: 0.1

sources: VULMON: CVE-2022-29181 // JVNDB: JVNDB-2022-011583 // CNNVD: CNNVD-202205-3804

EXTERNAL IDS

db:NVDid:CVE-2022-29181

Trust: 3.6

db:PACKETSTORMid:170314

Trust: 0.8

db:PACKETSTORMid:168080

Trust: 0.8

db:JVNDBid:JVNDB-2022-011583

Trust: 0.8

db:CNNVDid:CNNVD-202205-3804

Trust: 0.7

db:VULHUBid:VHN-420715

Trust: 0.1

db:VULMONid:CVE-2022-29181

Trust: 0.1

sources: VULHUB: VHN-420715 // VULMON: CVE-2022-29181 // JVNDB: JVNDB-2022-011583 // PACKETSTORM: 168080 // PACKETSTORM: 170314 // CNNVD: CNNVD-202205-3804 // NVD: CVE-2022-29181

REFERENCES

url:https://security.gentoo.org/glsa/202208-29

Trust: 1.9

url:https://support.apple.com/kb/ht213532

Trust: 1.8

url:https://github.com/sparklemotion/nokogiri/security/advisories/ghsa-xh29-r2w5-wx8m

Trust: 1.8

url:https://github.com/sparklemotion/nokogiri/commit/db05ba9a1bd4b90aa6c76742cf6102a7c7297267

Trust: 1.8

url:https://github.com/sparklemotion/nokogiri/releases/tag/v1.13.6

Trust: 1.8

url:https://securitylab.github.com/advisories/ghsl-2022-031_ghsl-2022-032_nokogiri/

Trust: 1.8

url:http://seclists.org/fulldisclosure/2022/dec/23

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2022-29181

Trust: 1.0

url:https://packetstormsecurity.com/files/168080/gentoo-linux-security-advisory-202208-29.html

Trust: 0.6

url:https://packetstormsecurity.com/files/170314/apple-security-advisory-2022-12-13-4.html

Trust: 0.6

url:https://access.redhat.com/security/cve/cve-2022-29181

Trust: 0.6

url:https://vigilance.fr/vulnerability/nokogiri-memory-corruption-38404

Trust: 0.6

url:https://support.apple.com/en-us/ht213532

Trust: 0.6

url:https://cxsecurity.com/cveshow/cve-2022-29181/

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2022-24836

Trust: 0.2

url:https://cwe.mitre.org/data/definitions/241.html

Trust: 0.1

url:https://alas.aws.amazon.com/alas-2022-1648.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:https://security.gentoo.org/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-26247

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-42841

Trust: 0.1

url:https://www.apple.com/support/security/pgp/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-32943

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-42847

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-42854

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-42840

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-42842

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-42845

Trust: 0.1

url:https://support.apple.com/en-us/ht201222.

Trust: 0.1

url:https://support.apple.com/ht213532.

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-42853

Trust: 0.1

url:https://support.apple.com/downloads/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-42843

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-42852

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-32942

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-42837

Trust: 0.1

sources: VULHUB: VHN-420715 // VULMON: CVE-2022-29181 // JVNDB: JVNDB-2022-011583 // PACKETSTORM: 168080 // PACKETSTORM: 170314 // CNNVD: CNNVD-202205-3804 // NVD: CVE-2022-29181

CREDITS

Gentoo

Trust: 0.1

sources: PACKETSTORM: 168080

SOURCES

db:VULHUBid:VHN-420715
db:VULMONid:CVE-2022-29181
db:JVNDBid:JVNDB-2022-011583
db:PACKETSTORMid:168080
db:PACKETSTORMid:170314
db:CNNVDid:CNNVD-202205-3804
db:NVDid:CVE-2022-29181

LAST UPDATE DATE

2024-08-14T12:55:53.318000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-420715date:2023-02-16T00:00:00
db:VULMONid:CVE-2022-29181date:2022-12-13T00:00:00
db:JVNDBid:JVNDB-2022-011583date:2023-08-23T00:23:00
db:CNNVDid:CNNVD-202205-3804date:2022-12-30T00:00:00
db:NVDid:CVE-2022-29181date:2023-02-16T02:31:15.450

SOURCES RELEASE DATE

db:VULHUBid:VHN-420715date:2022-05-20T00:00:00
db:VULMONid:CVE-2022-29181date:2022-05-20T00:00:00
db:JVNDBid:JVNDB-2022-011583date:2023-08-23T00:00:00
db:PACKETSTORMid:168080date:2022-08-15T16:03:50
db:PACKETSTORMid:170314date:2022-12-22T02:11:48
db:CNNVDid:CNNVD-202205-3804date:2022-05-19T00:00:00
db:NVDid:CVE-2022-29181date:2022-05-20T19:15:08.203