CVE Vulnerabilities

CVE-2023-24038

Published: Jan 21, 2023 | Modified: Apr 02, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The HTML-StripScripts module through 1.06 for Perl allows _hss_attval_style ReDoS because of catastrophic backtracking for HTML content with certain style attributes.

Affected Software

NameVendorStart VersionEnd Version
Html-stripscriptsHtml-stripscripts_project*1.06 (including)
Libhtml-stripscripts-perlUbuntubionic*
Libhtml-stripscripts-perlUbuntuesm-apps/bionic*
Libhtml-stripscripts-perlUbuntuesm-apps/focal*
Libhtml-stripscripts-perlUbuntuesm-apps/jammy*
Libhtml-stripscripts-perlUbuntuesm-apps/xenial*
Libhtml-stripscripts-perlUbuntufocal*
Libhtml-stripscripts-perlUbuntujammy*
Libhtml-stripscripts-perlUbuntukinetic*
Libhtml-stripscripts-perlUbuntulunar*
Libhtml-stripscripts-perlUbuntutrusty*
Libhtml-stripscripts-perlUbuntutrusty/esm*
Libhtml-stripscripts-perlUbuntuupstream*
Libhtml-stripscripts-perlUbuntuxenial*

References