Vulnerability Description
Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web pages, an attacker may supply content that causes HtmlUnit to crash by a stack overflow. This effect may support a denial of service attack.This issue affects htmlunit before 2.70.0.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Htmlunit | Htmlunit | < 2.70.0 |
Related Weaknesses (CWE)
References
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=54613Mailing List
- https://github.com/HtmlUnit/htmlunit/commit/940dc7fdPatch
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=54613Mailing List
- https://github.com/HtmlUnit/htmlunit/commit/940dc7fdPatch
FAQ
What is CVE-2023-2798?
CVE-2023-2798 is a vulnerability with a CVSS score of 7.5 (HIGH). Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web pages, an attacker may supply content that causes Ht...
How severe is CVE-2023-2798?
CVE-2023-2798 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-2798?
Check the references section above for vendor advisories and patch information. Affected products include: Htmlunit Htmlunit.