CVE-2023-34624 - Denial of Service (DoS)
Severity: High2023-07-19
Abstract
An issue was discovered htmlcleaner thru = 2.28 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
The Oxygen products incorporate htmlcleaner as a third-party library. This advisory was opened to address the potential impact of this third-party library vulnerability.
Affected Products/Versions
Product | Severity | Fixed Release Availability |
Oxygen XML Author v25.1 and older | High | Oxygen XML Author 25.1 build 2023070306 |
Oxygen XML Developer v25.1 and older | High | Oxygen XML Developer 25.1 build 2023070306 |
Oxygen XML Editor v25.1 and older | High | Oxygen XML Editor 25.1 build 2023070306 |
Oxygen PDF Chemistry v25.1 and older | High | Oxygen PDF Chemistry 25.1 build 2023063023 |
Detail
CVE-2023-34624
Severity: High
CVSS Score: 7.5
The htmlcleaner third-party library used by Oxygen XML products is an affected version mentioned in CVE-2023-34624 vulnerability description.
Starting with Oxygen XML v25.1 build 2023070306 htmlcleaner library was updated to v2.29 which fixes this vulnerability.