Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-28367

Опубликовано: 21 апр. 2022
Источник: debian
EPSS Низкий

Описание

OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libowasp-antisamy-javafixed1.7.4-1package
libowasp-antisamy-javaignoredbookwormpackage
libowasp-antisamy-javano-dsabullseyepackage
libowasp-antisamy-javano-dsabusterpackage
libowasp-antisamy-javano-dsastretchpackage

Примечания

  • https://github.com/nahsra/antisamy/commit/0199e7e194dba5e7d7197703f43ebe22401e61ae (v1.6.6)

  • Make sure to fix the issue completely and include the commit otherwise opening CVE-2022-29577

  • https://github.com/nahsra/antisamy/commit/32e273507da0e964b58c50fd8a4c94c9d9363af0 (v1.6.7)

EPSS

Процентиль: 59%
0.00995
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 4 лет назад

OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content.

CVSS3: 6.1
nvd
больше 4 лет назад

OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content.

CVSS3: 6.1
github
больше 4 лет назад

Cross-site Scripting in OWASP AntiSamy

EPSS

Процентиль: 59%
0.00995
Низкий