QID 981276

QID 981276: Java (maven) Security Update for org.owasp.antisamy:antisamy (GHSA-683w-6h9j-57wq)

In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-683w-6h9j-57wq for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981276

    Software Advisories
    Advisory ID Software Component Link
    GHSA-683w-6h9j-57wq org.owasp.antisamy:antisamy URL Logo github.com/advisories/GHSA-683w-6h9j-57wq