Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:4011-1

Опубликовано: 16 нояб. 2022
Источник: suse-cvrf

Описание

Security update for jsoup

This update for jsoup fixes the following issues:

Updated to version 1.15.3:

  • CVE-2022-36033: Fixed incorrect sanitization of user input in SafeList.preserveRelativeLinks (bsc#1203459).

Список пакетов

Container bci/openjdk-devel:11
jsoup-1.15.3-150200.3.6.1
Container bci/openjdk-devel:17
jsoup-1.15.3-150200.3.6.1
Container bci/openjdk-devel:latest
jsoup-1.15.3-150200.3.6.1
SUSE Linux Enterprise Module for Development Tools 15 SP3
jsoup-1.15.3-150200.3.6.1
SUSE Linux Enterprise Module for Development Tools 15 SP4
jsoup-1.15.3-150200.3.6.1
openSUSE Leap 15.3
jsoup-1.15.3-150200.3.6.1
jsoup-javadoc-1.15.3-150200.3.6.1
openSUSE Leap 15.4
jsoup-1.15.3-150200.3.6.1
jsoup-javadoc-1.15.3-150200.3.6.1

Описание

jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks` option is enabled, HTML including `javascript:` URLs that have been crafted with control characters will not be sanitized. If the site that this HTML is published on does not set a Content Security Policy, an XSS attack is then possible. This issue is patched in jsoup 1.15.3. Users should upgrade to this version. Additionally, as the unsanitized input may have been persisted, old content should be cleaned again using the updated version. To remediate this issue without immediately upgrading: - disable `SafeList.preserveRelativeLinks`, which will rewrite input URLs as absolute URLs - ensure an appropriate [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) is defined. (This should be used regardless of upgrading, as a defence-in-depth best practice.)


Затронутые продукты
Container bci/openjdk-devel:11:jsoup-1.15.3-150200.3.6.1
Container bci/openjdk-devel:17:jsoup-1.15.3-150200.3.6.1
Container bci/openjdk-devel:latest:jsoup-1.15.3-150200.3.6.1
SUSE Linux Enterprise Module for Development Tools 15 SP3:jsoup-1.15.3-150200.3.6.1

Ссылки