Reflected cross-site scripting (XSS) In libowasp-antisamy-java
Description
OWASP AntiSamy vulnerable to Cross-site Scripting In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | - | ||
debian 12 | - | ||
debian 13 | 1.7.4-1 | ||
debian 14 | 1.7.4-1 | ||
maven | 1.5.5 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4.