An issue was discovered jtidy thru r938 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade jtidyUpgrade jtidy-javadoc | Feb 21, 2024 | Jun 14, 2023 |
| Debian | — | No solution exists | May 15, 2025 | Jun 14, 2023 |
| Suse | — | Upgrade jtidy-scriptsUpgrade jtidyUpgrade jtidy-javadoc | Jul 31, 2023 | Jun 14, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub