GHSA-h975-r69h-4w9p
Dashboard / Vulnerabilities / GHSA-h975-r69h-4w9p
Summary: Insufficient user input in Apache Jetspeed-2
Details: ** UNSUPPORTED WHEN ASSIGNED ** Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dormant project of Apache Portals and no updates will be provided for this issue.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-32533, https://lists.apache.org/thread/d3g248pr03x8rvmh8p2t3xdlw0wn5dz2, https://www.openwall.com/lists/oss-security/2022/07/06/1, http://www.openwall.com/lists/oss-security/2022/07/06/1
Affected packages
Package
Name: org.apache.portals.jetspeed-2:jetspeed-commons
Purl: pkg:maven/org.apache.portals.jetspeed-2/jetspeed-commons
Affected ranges
Type: ECOSYSTEM
Events:
