CVE-2022-36033

CVSS v3.1 6.1 (Medium)
61% Progress
EPSS 0.11 % (45th)
0.11% Progress
Affected Products 4
Advisories 3

jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including javascript: URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default SafeList.preserveRelativeLinks option is enabled, HTML including javascript: URLs that have been crafted with control characters will not be sanitized. If the site that this HTML is published on does not set a Content Security Policy, an XSS attack is then possible. This issue is patched in jsoup 1.15.3. Users should upgrade to this version. Additionally, as the unsanitized input may have been persisted, old content should be cleaned again using the updated version. To remediate this issue without immediately upgrading: - disable SafeList.preserveRelativeLinks, which will rewrite input URLs as absolute URLs - ensure an appropriate Content Security Policy is defined. (This should be used regardless of upgrading, as a defence-in-depth best practice.)

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-87
Improper Neutralization of Alternate XSS Syntax
CVE Status
PUBLISHED
CNA
GitHub, Inc.
Published Date
2022-08-29 17:15:08
(2 years ago)
Updated Date
2022-12-08 03:48:04
(21 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jsoup prior 1.15.3 version cpe:2.3:a:jsoup:jsoup < 1.15.3

Configuration #2

    CPE23 From Up To
  Netapp Management Services for Element Software cpe:2.3:a:netapp:management_services_for_element_software:-
  Management Services for Netapp Hci cpe:2.3:a:netapp:management_services_for_netapp_hci:-
  Netapp Oncommand Workflow Automation cpe:2.3:a:netapp:oncommand_workflow_automation:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...