PT-2023-24675 · Unknown · Fast-Xml-Parser

7085

·

Publicado

2023-06-06

·

Atualizado

2026-03-09

·

CVE-2023-34104

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions fast-xml-parser versions prior to 4.2.4
Description The issue allows special characters in entity names, which are not escaped or sanitized. This can be abused for denial of service (DoS) attacks by crafting an entity name that results in an intentionally bad performing regex, causing the parser to stall for an indefinite amount of time.
Recommendations For versions prior to 4.2.4, upgrade to version 4.2.4 or later. For users unable to upgrade, avoid using DOCTYPE parsing by setting the processEntities: false option.

Exploit

Correção

DoS

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-34104
GHSA-6W63-H3FJ-Q4VW

Produtos afetados

Fast-Xml-Parser