Skip to main content

Cyber security vulnerability issue raised regarding libwebp (CVE-2023-5129)

Is Abacus affected by the cyber security libwebp (CVE-2023-5129) issue?

D
Written by David Bayley-Hamilton
Updated this week

CVE-2023-5129 is a duplicate of CVE-2023-4863. This vulnerability relates to Google Chrome and WebP support.
​
Google patched this vulnerability in Chrome on 11th September 2023 in version 116.0.5848.187/188 and Microsoft patched Edge on 15th September 2023 in version 109.0.1518.140/117.0.2045.31.
​
Whilst Google Chrome and Microsoft Edge can be used to access Abacus Admin and Provider Portal, the product does not contain or use images in the WebP format. Also, the product does not utilise LibWebP, nor do any product dependencies.
​
Therefore Abacus Abacus Admin and Provider Portal are not affected by this vulnerability.

Did this answer your question?