PT-2023-28331 · Lol-Html · Lol-Html

Inikulin

·

Published

2023-08-09

·

Updated

2023-08-22

·

CVE-2023-4241

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions lol-html versions prior to 1.1.1
Description The issue causes panics on certain HTML inputs. Anyone processing arbitrary 3rd party HTML with the library is affected.
Recommendations For versions prior to 1.1.1, update to version 1.1.1 to resolve the issue. As a temporary workaround, consider avoiding the processing of arbitrary 3rd party HTML with the library until the update is applied.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2023-4241
GHSA-C3X7-354F-4P2X

Affected Products

Lol-Html