Skip to content

This issue was moved to a discussion.

You can continue the conversation there. Go to discussion →

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Validator.isValidSafeHTML() is vulnerable as per CVE-2023-4780 #835

Closed
Adwait-Joshi94 opened this issue Mar 10, 2024 · 1 comment
Closed
Labels

Comments

@Adwait-Joshi94
Copy link

Hi Team,

Our organization has filed security finding in our application because of usagae of ESAPI open source library in our application. Based on investigation, finding is filed because of CVE-2023-4780, presence of method Validator.isValidSafeHTML(). As per GHSA-r68h-jhhj-9jvm , this method will be deleted in next one year. We would like to know in which release this method will be deleted and if there is any short term remediation through which we can resolve this finding?

Thanks,
Adwait Joshi

@jeremiahjstacey
Copy link
Collaborator

https://github.com/ESAPI/esapi-java-legacy/blob/develop/documentation/ESAPI-security-bulletin12.pdf

Security Bulletin should provide information being requested.

@ESAPI ESAPI locked and limited conversation to collaborators Mar 10, 2024
@jeremiahjstacey jeremiahjstacey converted this issue into discussion #836 Mar 10, 2024

This issue was moved to a discussion.

You can continue the conversation there. Go to discussion →

Labels
Projects
None yet
Development

No branches or pull requests

2 participants