Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-35043

Опубликовано: 19 июл. 2021
Источник: redhat
CVSS3: 8.8

Описание

OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for the : character.

A flaw was found in AnitSamy, where it allows a Cross-site Scripting attack (XSS) via HTML attributes when using the HTML output serializer (XHTML is not affected). This issue was demonstrated by a javascript: URL with : as the replacement for the : character. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Отчет

Marking Red Hat JBoss Fuse 6 as having a low impact. Although AntiSamy is present in the offline repository, it is not used. This vulnerability is out of security support scope for the following products:

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Fuse 6OWASP AntiSamyOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 4 лет назад

OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for the : character.

CVSS3: 6.1
nvd
больше 4 лет назад

OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for the : character.

CVSS3: 6.1
debian
больше 4 лет назад

OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using ...

CVSS3: 6.1
github
больше 4 лет назад

Cross-site Scripting in OWASP AntiSamy

CVSS3: 6.1
fstec
больше 4 лет назад

Уязвимость библиотеки для выполнения быстрой настраиваемой очистки HTML AntiSamy, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю осуществлять межсайтовые сценарные атаки

8.8 High

CVSS3