Описание
In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libowasp-antisamy-java | fixed | 1.7.4-1 | package | |
| libowasp-antisamy-java | ignored | bookworm | package | |
| libowasp-antisamy-java | no-dsa | bullseye | package | |
| libowasp-antisamy-java | no-dsa | buster | package | |
| libowasp-antisamy-java | no-dsa | stretch | package |
Примечания
https://github.com/nahsra/antisamy/issues/2
EPSS
Процентиль: 76%
0.00992
Низкий
Связанные уязвимости
CVSS3: 6.1
ubuntu
около 9 лет назад
In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.
CVSS3: 6.1
nvd
около 9 лет назад
In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.
CVSS3: 6.1
github
больше 7 лет назад
OWASP AntiSamy vulnerable to Cross-site Scripting
EPSS
Процентиль: 76%
0.00992
Низкий