PT-2022-18975 · Owasp+2 · Owasp Antisamy+4
Published
2022-04-21
·
Updated
2023-12-07
·
CVE-2022-28366
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
HtmlUnit-Neko versions 2.26 and earlier
CyberNeko HTML versions 1.9.22 and earlier
OWASP AntiSamy versions 1.6.6 and earlier
Description
Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption.
Recommendations
For HtmlUnit-Neko versions 2.26 and earlier, update to version 2.27 to resolve the issue.
For CyberNeko HTML versions 1.9.22 and earlier, consider disabling the affected HTML parser until an alternative solution is available, as 1.9.22 is the last version of CyberNeko HTML.
For OWASP AntiSamy versions 1.6.6 and earlier, update to version 1.6.6 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Confluence
Debian
Jira
Jira Service Management Server
Owasp Antisamy