CVE-2023-23617: OpenMage LTS has DoS vulnerability in MaliciousCode filter
OpenMage LTS is an e-commerce platform. Versions prior to 19.4.22 and 20.0.19 contain an infinite loop in malicious code filter in certain conditions. Versions 19.4.22 and 20.0.19 have a fix for this issue. There are no known workarounds.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-23617?
CVE-2023-23617 is a vulnerability in OpenMage LTS, an e-commerce platform, that allows for an infinite loop in the malicious code filter under certain conditions.
What is the severity of CVE-2023-23617?
CVE-2023-23617 has a severity level of high, with a CVSS score of 7.5.
Which versions of OpenMage LTS are affected by CVE-2023-23617?
Versions prior to 19.4.22 and 20.0.19 of OpenMage LTS are affected by CVE-2023-23617.
How can I fix CVE-2023-23617?
To fix CVE-2023-23617, you should update your OpenMage LTS installation to version 19.4.22 or 20.0.19, which contain a fix for this vulnerability.
Are there any workarounds for CVE-2023-23617?
There are no known workarounds for CVE-2023-23617, so it is recommended to update your OpenMage LTS installation to a fixed version.