[MAVEN:GHSA-683W-6H9J-57WQ] Moderate severity vulnerability that affects org.owasp.antisamy:antisamy

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.

Package Affected Version
pkg:maven/org.owasp.antisamy/antisamy < 1.5.5
Package Fixed Version
pkg:maven/org.owasp.antisamy/antisamy = 1.5.5
ID
MAVEN:GHSA-683W-6H9J-57WQ
Severity
moderate
URL
https://github.com/advisories/GHSA-683w-6h9j-57wq
Published
2018-10-18T17:21:47
(6 years ago)
Modified
2023-01-09T05:02:33
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.owasp.antisamy/antisamy org.owasp.antisamy antisamy < 1.5.5
Fixed pkg:maven/org.owasp.antisamy/antisamy org.owasp.antisamy antisamy = 1.5.5
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...