Asciidoctor allows remote attackers to cause a denial of service (infinite loop), as demonstrated by web applications that deliver untrusted input to this product, because Parser#next_block misuses a "while true" statement.
Upstream issue:
https://github.com/asciidoctor/asciidoctor/issues/2888
Statement:
The version of rubygem-asciidoctor included in Red Hat Virtualization is affected by this flaw, however it is not exposed to user input in such a way that the vulnerability could be exploited by an attacker.