CVE-2023-34624 - Denial of Service (DoS)

Severity: High2023-07-19

Security Advisories

Abstract

An issue was discovered htmlcleaner thru = 2.28 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.

The Oxygen products incorporate htmlcleaner as a third-party library. This advisory was opened to address the potential impact of this third-party library vulnerability.

Affected Products/Versions

ProductSeverityFixed Release Availability
Oxygen XML Author v25.1 and olderHigh Oxygen XML Author 25.1 build 2023070306
Oxygen XML Developer v25.1 and olderHigh Oxygen XML Developer 25.1 build 2023070306
Oxygen XML Editor v25.1 and olderHigh Oxygen XML Editor 25.1 build 2023070306
Oxygen PDF Chemistry v25.1 and olderHigh Oxygen PDF Chemistry 25.1 build 2023063023

Mitigation

None

Detail

CVE-2023-34624

Severity: High

CVSS Score: 7.5

The htmlcleaner third-party library used by Oxygen XML products is an affected version mentioned in CVE-2023-34624 vulnerability description.

Starting with Oxygen XML v25.1 build 2023070306 htmlcleaner library was updated to v2.29 which fixes this vulnerability.

List of Security Advisories