SB2023020756 - Denial of service in HTML-StripScripts
Published: February 7, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect Regular Expression (CVE-ID: CVE-2023-24038)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation when processing untrusted input in _hss_attval_style. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.