Опубликовано: 21 апр. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 6.1
Описание
OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needs-triage |
| devel | needs-triage | |
| esm-apps-legacy/xenial | needs-triage | |
| esm-apps/bionic | needs-triage | |
| esm-apps/focal | needs-triage | |
| esm-apps/jammy | needs-triage | |
| esm-apps/noble | needs-triage | |
| esm-apps/resolute | needs-triage | |
| esm-apps/xenial | ignored | end of ESM support, was needs-triage |
| focal | ignored | end of standard support, was needs-triage |
Показывать по
10
Ссылки на источники
EPSS
Процентиль: 60%
0.00995
Низкий
4.3 Medium
CVSS2
6.1 Medium
CVSS3
Связанные уязвимости
CVSS3: 6.1
nvd
больше 4 лет назад
OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content.
CVSS3: 6.1
debian
больше 4 лет назад
OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE ...
EPSS
Процентиль: 60%
0.00995
Низкий
4.3 Medium
CVSS2
6.1 Medium
CVSS3