PT-2021-23638 · Owasp · Owasp Java Html Sanitizer

Published

2021-10-18

·

Updated

2023-02-24

·

CVE-2021-42575

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OWASP Java HTML Sanitizer versions prior to 20211018.1
Description The issue is related to the improper enforcement of policies associated with the SELECT, STYLE, and OPTION elements. This affects the OWASP Java HTML Sanitizer.
Recommendations For versions prior to 20211018.1, update to version 20211018.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the SELECT, STYLE, and OPTION elements until a patch is applied.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2021-42575
GHSA-3W73-FMF3-HG5C
RHSA-2022:7409
RHSA-2022:7410
RHSA-2022:7411

Affected Products

Owasp Java Html Sanitizer