Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-66021

Опубликовано: 26 нояб. 2025
Источник: redhat
CVSS3: 7.1

Описание

OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by third-parties in web applications while protecting against XSS. In version 20240325.1, OWASP java html sanitizer is vulnerable to XSS if HtmlPolicyBuilder allows noscript and style tags with allowTextIn inside the style tag. This could lead to XSS if the payload is crafted in such a way that it does not sanitise the CSS and allows tags which is not mentioned in HTML policy. At time of publication no known patch is available.

A cross site scripting flaw has been discovered in the OWASP Java HTML Sanitizer. If HtmlPolicyBuilder allows noscript and style tags with allowTextIn inside the style tag. This could lead to XSS if the payload is crafted in such a way that it does not sanitise the CSS and allows tags which is not mentioned in HTML policy. This may allow an attacker to execute javascript in the context of a user's browser.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftowasp-java-html-sanitizerWill not fix
OpenShift Developer Tools and ServicesjenkinsAffected
OpenShift Developer Tools and Servicesjenkins-2-pluginsAffected
Red Hat JBoss Enterprise Application Platform 8owasp-java-html-sanitizerNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packowasp-java-html-sanitizerNot affected
Red Hat Single Sign-On 7owasp-java-html-sanitizerWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2417190com.googlecode.owasp-java-html-sanitizer/owasp-java-html-sanitizer: OWASP Java HTML Sanitizer vulnerable to XSS

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
4 месяца назад

OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by third-parties in web applications while protecting against XSS. In version 20240325.1, OWASP java html sanitizer is vulnerable to XSS if HtmlPolicyBuilder allows noscript and style tags with allowTextIn inside the style tag. This could lead to XSS if the payload is crafted in such a way that it does not sanitise the CSS and allows tags which is not mentioned in HTML policy. At time of publication no known patch is available.

github
4 месяца назад

OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization

7.1 High

CVSS3