[MAVEN:GHSA-G8JJ-899Q-8X3J] Cross-site scripting in json-sanitizer

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

OWASP json-sanitizer before 1.2.1 allows XSS. An attacker who controls a substring of the input JSON, and controls another substring adjacent to a SCRIPT element in which the output is embedded as JavaScript, may be able to confuse the HTML parser as to where the SCRIPT element ends, and cause non-script content to be interpreted as JavaScript.

Package Affected Version
pkg:maven/com.mikesamuel/json-sanitizer < 1.2.1
Package Fixed Version
pkg:maven/com.mikesamuel/json-sanitizer = 1.2.1
ID
MAVEN:GHSA-G8JJ-899Q-8X3J
Severity
moderate
URL
https://github.com/advisories/GHSA-g8jj-899q-8x3j
Published
2022-02-10T23:04:13
(2 years ago)
Modified
2023-02-01T05:05:44
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.mikesamuel/json-sanitizer com.mikesamuel json-sanitizer < 1.2.1
Fixed pkg:maven/com.mikesamuel/json-sanitizer com.mikesamuel json-sanitizer = 1.2.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...