CVE-2022-2421 - Remote Code Execution (RCE)

Severity: Critical2023-01-06

Security Advisories


Due to improper type validation in attachment parsing the js library, it is possible to overwrite the _placeholder object which allows an attacker to place references to functions at arbitrary places in the resulting query object.

The Oxygen products incorporate as a third-party library. This advisory was opened to address the potential impact of this third-party library vulnerability.

Affected Products/Versions

ProductSeverityFixed Release Availability
Oxygen Content Fusion v5.0.1 and olderCritical Oxygen Content Fusion 5.0.2 build 2022121305





Severity: Critical

CVSS Score: 9.8

The third-party library used by Oxygen XML products is an affected version mentioned in CVE-2022-2421 vulnerability description.

List of Security Advisories