PT-2022-21354 · Apache · Apache Jetspeed-2

Runningsnail

+1

·

Published

2022-07-06

·

Updated

2024-08-03

·

CVE-2022-32533

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Jetspeed-2 (affected versions not specified)
Description The issue arises from insufficient filtering of untrusted user input by default, leading to problems such as XSS, CSRF, XXE, and SSRF. Setting the configuration option xss.filter.post = true may help mitigate these issues. It's noted that Apache Jetspeed is a dormant project of Apache Portals, and no updates will be provided for this issue.
Recommendations As a temporary workaround, consider setting the configuration option xss.filter.post = true to mitigate the issues. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

XSS

CSRF

XXE

Weakness Enumeration

Related Identifiers

CVE-2022-32533
GHSA-H975-R69H-4W9P

Affected Products

Apache Jetspeed-2