7.5
CVSSv3

CVE-2023-34624

Published: 14/06/2023 Updated: 08/08/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists htmlcleaner thru = 2.28 allows malicious users to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.

Vulnerable Product Search on Vulmon Subscribe to Product

htmlcleaner project htmlcleaner

Vendor Advisories

A security vulnerability has been discovered in libhtmlcleaner-java, a Java HTML parser library An attacker was able to cause a denial of service (StackOverflowError) if the parser runs on user supplied input with deeply nested HTML elements This update introduces a new nesting depth limit which can be overridden in cleaner properties For the ol ...