CVE-2023-34623
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jun 14, 2023
Updated: Jan 3, 2025
CWE ID 787
Summary
CVE-2023-34623 is a newly identified vulnerability affecting jtidy, a library used for HTML and XML parsing, up to version r938. This issue grants attackers the ability to cause a denial of service or unspecified impacts by utilizing crafted objects containing cyclic dependencies. The exact nature of these impacts remains undefined, but it is recommended that users update to the latest version of jtidy to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.