Skip to content

Moderate severity vulnerability that affects org.owasp.antisamy:antisamy

Moderate severity GitHub Reviewed Published Oct 18, 2018 to the GitHub Advisory Database • Updated Jan 9, 2023
Withdrawn This advisory was withdrawn on Jun 16, 2020

Package

maven org.owasp.antisamy:antisamy (Maven)

Affected versions

<= 1.5.7

Patched versions

None

Description

OWASP OWASP ANTISAMY version 1.5.7 and earlier contains a Cross Site Scripting (XSS) vulnerability in AntiSamy.scan() - for both SAX & DOM that can result in Cross Site Scripting.

References

Published to the GitHub Advisory Database Oct 18, 2018
Reviewed Jun 16, 2020
Withdrawn Jun 16, 2020
Last updated Jan 9, 2023

Severity

Moderate

Weaknesses

No CWEs

CVE ID

CVE-2018-1000643

GHSA ID

GHSA-xv6v-72hh-g6g2

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.