PT-2015-3451 · Jsoup+1 · Jsoup+1

Hardy Ferentschik

·

Published

2015-07-06

·

Updated

2024-08-16

·

CVE-2015-6748

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions jsoup versions prior to 1.8.3
Description The issue is related to a lack of protection for the structure of web pages, which can be exploited to perform cross-site scripting (XSS) attacks. This allows a remote attacker to carry out XSS attacks.
Recommendations For versions prior to 1.8.3, update to version 1.8.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the jsoup library until a patch is applied.

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2366
BDU:2024-01744
CVE-2015-6748
DLA-2075-1
GHSA-48RH-QGJR-XFJ6
MGASA-2015-0340

Affected Products

Alt Linux
Jsoup