VulnerabilityModified
CVE-2021-35043
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected).
MEDIUM 6.1EPSS 1.51%
Does this matter?
Lower severity and a low EPSS score (1.51%). Track it; it rarely justifies an emergency change on its own.
Description
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.51% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- antisamy project/antisamy · oracle/retail back office · oracle/retail central office · oracle/retail returns management · oracle/banking enterprise default management · oracle/banking enterprise default managment · oracle/banking party management · oracle/banking platform · oracle/insurance policy administration · oracle/middleware common libraries and tools · netapp/active iq unified manager
- Source
- cve@mitre.org
References
- https://github.com/nahsra/antisamy/pull/87Patch, Third Party Advisory
- https://github.com/nahsra/antisamy/releases/tag/v1.6.4Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- https://github.com/nahsra/antisamy/pull/87Patch, Third Party Advisory
- https://github.com/nahsra/antisamy/releases/tag/v1.6.4Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.