First published: Fri Jan 27 2023(Updated: )
OpenMage LTS is an e-commerce platform. Versions prior to 19.4.22 and 20.0.19 contain an infinite loop in malicious code filter in certain conditions. Versions 19.4.22 and 20.0.19 have a fix for this issue. There are no known workarounds.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenMage | <19.4.22 | |
OpenMage | >=20.0.0<20.0.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23617 is a vulnerability in OpenMage LTS, an e-commerce platform, that allows for an infinite loop in the malicious code filter under certain conditions.
CVE-2023-23617 has a severity level of high, with a CVSS score of 7.5.
Versions prior to 19.4.22 and 20.0.19 of OpenMage LTS are affected by CVE-2023-23617.
To fix CVE-2023-23617, you should update your OpenMage LTS installation to version 19.4.22 or 20.0.19, which contain a fix for this vulnerability.
There are no known workarounds for CVE-2023-23617, so it is recommended to update your OpenMage LTS installation to a fixed version.