PT-2022-18975 · Owasp+2 · Owasp Antisamy+4

Published

2022-04-21

·

Updated

2023-12-07

·

CVE-2022-28366

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions HtmlUnit-Neko versions 2.26 and earlier CyberNeko HTML versions 1.9.22 and earlier OWASP AntiSamy versions 1.6.6 and earlier
Description Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption.
Recommendations For HtmlUnit-Neko versions 2.26 and earlier, update to version 2.27 to resolve the issue. For CyberNeko HTML versions 1.9.22 and earlier, consider disabling the affected HTML parser until an alternative solution is available, as 1.9.22 is the last version of CyberNeko HTML. For OWASP AntiSamy versions 1.6.6 and earlier, update to version 1.6.6 or later to resolve the issue.

Fix

Related Identifiers

CVE-2022-28366
GHSA-G9HH-VVX3-V37V
OPENSUSE-SU-2024:12022-1

Affected Products

Confluence
Debian
Jira
Jira Service Management Server
Owasp Antisamy