First published: Tue Jul 25 2023(Updated: )
> ### CVSS: `CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N/E:F/RL:O/RC:C` (4.4) ### Problem Due to an encoding issue in the serialization layer, malicious markup nested in a `noscript` element was not encoded correctly. `noscript` is disabled in the default configuration, but might have been enabled in custom scenarios. This allows bypassing the cross-site scripting mechanism of [`typo3/html-sanitizer`](https://packagist.org/packages/typo3/html-sanitizer). ### Solution Update to `typo3/html-sanitizer` versions 1.5.1 or 2.1.2 that fix the problem described. ### Credits Thanks to David Klein and Yaniv Nizry who reported this issue, and to TYPO3 security team members Oliver Hader and Benjamin Franzke who fixed the issue. ### References * [TYPO3-CORE-SA-2023-002](https://typo3.org/security/advisory/typo3-core-sa-2023-002)
Credit: security-advisories@github.com security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/typo3/html-sanitizer | >=2.0.0<2.1.2 | 2.1.2 |
composer/typo3/html-sanitizer | >=1.0.0<1.5.1 | 1.5.1 |
TYPO3 HTML Sanitizer | >=1.0.0<1.5.1 | |
TYPO3 HTML Sanitizer | >=2.0.0<2.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-38500 is medium with a CVSS score of 6.1.
The affected software for CVE-2023-38500 is TYPO3 HTML Sanitizer versions between 2.0.0 and 2.1.2, and versions between 1.0.0 and 1.5.1.
To fix CVE-2023-38500, update TYPO3 HTML Sanitizer to version 2.1.2 for versions 2.0.0 to 2.1.2, or update to version 1.5.1 for versions 1.0.0 to 1.5.1.
The CWE for CVE-2023-38500 is CWE-79 (Improper Neutralization of Input During Web Page Generation).
You can find more information about CVE-2023-38500 in the following references: [GitHub Security Advisory](https://github.com/TYPO3/html-sanitizer/security/advisories/GHSA-59jf-3q9v-rh6g), [GitHub Commit](https://github.com/TYPO3/html-sanitizer/commit/e3026f589fef0be8c3574ee3f0a0bfbe33d7ebdb), [TYPO3 Security Advisory](https://typo3.org/security/advisory/typo3-core-sa-2023-002).