GHSA-7mfw-43c4-45mq

    Dashboard / Vulnerabilities / GHSA-7mfw-43c4-45mq

    GHSA-7mfw-43c4-45mq

    Published: 14 May 2022Last Modified: 8 Nov 2023

    Summary: Cross-site Scripting in Apache Sling XSS Protection API

    Details: A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they carry XSS payloads. The affected versions are Apache Sling XSS Protection API 1.0.4 to 1.0.18, Apache Sling XSS Protection API Compat 1.1.0 and Apache Sling XSS Protection API 2.0.0.

    Affected packages

    Package

    Name: org.apache.sling:org.apache.sling.xss

    Purl: pkg:maven/org.apache.sling/org.apache.sling.xss

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 1.0.4
    Fixed -2.0.4

    Affected versions

    1.0.12
    1.0.14
    1.0.16
    1.0.18
    1.0.4
    1.0.6
    1.0.8

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High