Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-40403

Опубликовано: 26 сент. 2023
Источник: redhat
CVSS3: 6.5

Описание

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may disclose sensitive information.

A flaw was found in libxslt package. Processing web content may disclose sensitive information. This issue was addressed with improved memory handling.

Отчет

This CVE is a duplicate of CVE-2022-4909. Within regulated environments, a combination of the following controls acts as a significant barrier to successfully exploiting a CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability and therefore downgrades the severity of this particular CVE from Moderate to Low. Access to the platform is granted only after successful hard token, multi-factor authentication (MFA), which is coupled with account management controls, including integration with single sign-on (SSO), to ensure that user permissions are restricted to only the functions necessary for their roles. Access to sensitive information is explicitly authorized and enforced based on predefined access policies. Event logs are collected and processed for centralization, correlation, analysis, monitoring, reporting, alerting, and retention. This process ensures that audit logs are generated for specific events involving sensitive information, which helps identify patterns of unauthorized access or data exposure. The platform enforces the use of validated cryptographic modules across compute resources to protect the confidentiality of information, even in the event of interception.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libxsltFix deferred
Red Hat Enterprise Linux 6libxsltOut of support scope
Red Hat Enterprise Linux 7libxsltOut of support scope
Red Hat Enterprise Linux 9libxsltAffected
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 8libxsltFixedRHSA-2025:867609.06.2025
Red Hat Enterprise Linux 8libxsltFixedRHSA-2025:867609.06.2025
Red Hat Enterprise Linux 9.4 Extended Update SupportlibxsltFixedRHSA-2025:901612.06.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2349766libxslt: Processing web content may disclose sensitive information

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may disclose sensitive information.

CVSS3: 6.5
github
больше 1 года назад

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may disclose sensitive information.

oracle-oval
10 дней назад

ELSA-2025-8676: libxslt security update (MODERATE)

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость библиотеки libxslt операционной системы iPadOS, tvOS, iOS, watchOS, macOS, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

suse-cvrf
3 месяца назад

Security update for libxslt

6.5 Medium

CVSS3