CVE-2022-29577
Summary
| CVE | CVE-2022-29577 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-21 23:15:00 UTC |
| Updated | 2023-02-23 18:47:00 UTC |
| Description | OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. NOTE: this issue exists because of an incomplete fix for CVE-2022-28367. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Release Release version 1.6.7 · nahsra/antisamy · GitHub |
MISC |
github.com |
|
| Fix child node removal on style tag processing · nahsra/antisamy@32e2735 · GitHub |
MISC |
github.com |
|
| Oracle Critical Patch Update Advisory - July 2022 |
N/A |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 87496 Oracle WebLogic Server Multiple Vulnerabilities (CPUJUL2022)