CVE Vulnerabilities

CVE-2023-23617

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jan 28, 2023 | Modified: Feb 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

OpenMage LTS is an e-commerce platform. Versions prior to 19.4.22 and 20.0.19 contain an infinite loop in malicious code filter in certain conditions. Versions 19.4.22 and 20.0.19 have a fix for this issue. There are no known workarounds.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Magento Openmage * 19.4.22 (excluding)
Magento Openmage 20.0.0 (including) 20.0.19 (excluding)

References