Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-34623

Опубликовано: 14 июн. 2023
Источник: redhat
CVSS3: 7.5

Описание

An issue was discovered jtidy thru r938 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.

A flaw was found in jtidy when parsing untrusted html. If the parser is running on unsanitized user input, an attacker could craft a request that causes the parser to crash by stack overflow, resulting in a denial of service (DoS).

Меры по смягчению последствий

This flaw can be mitigated by implementing sanitization against excessive nesting in user requests.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2jtidyNot affected
Cryostat 2jtidyNot affected
Migration Toolkit for Applications 6org.jboss.windup.plugin-windup-maven-plugin-parentWill not fix
Migration Toolkit for Runtimesorg.jboss.windup.plugin-windup-maven-plugin-parentWill not fix
OpenShift Developer Tools and ServicesjenkinsNot affected
Red Hat AMQ Broker 7jtidyNot affected
Red Hat build of Apache Camel for Spring Boot 3jtidyNot affected
Red Hat build of Apicurio Registry 2jtidyNot affected
Red Hat build of Debezium 1jtidyNot affected
Red Hat build of Debezium 2jtidyNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2215234jtidy: denial of service via crafted object that uses cyclic dependencies

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 лет назад

An issue was discovered jtidy thru r938 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.

CVSS3: 7.5
nvd
около 2 лет назад

An issue was discovered jtidy thru r938 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.

CVSS3: 7.5
debian
около 2 лет назад

An issue was discovered jtidy thru r938 allows attackers to cause a de ...

suse-cvrf
почти 2 года назад

Security update for jtidy

suse-cvrf
почти 2 года назад

Security update for jtidy

7.5 High

CVSS3