UBUNTU-CVE-2023-43643
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-43643
Summary:
Details: AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to version 1.7.4, there is a potential for a mutation XSS (mXSS) vulnerability in AntiSamy caused by flawed parsing of the HTML being sanitized. To be subject to this vulnerability the `preserveComments` directive must be enabled in your policy file and also allow for certain tags at the same time. As a result, certain crafty inputs can result in elements in comment tags being interpreted as executable when using AntiSamy's sanitized output. This issue has been patched in AntiSamy 1.7.4 and later.
References: https://ubuntu.com/security/CVE-2023-43643, https://github.com/nahsra/antisamy/security/advisories/GHSA-pcf2-gh6g-h5r2, https://github.com/nahsra/antisamy/commit/05c52b98bb845b8175b8406bd2f391ce334a05d6, https://github.com/nahsra/antisamy/releases/tag/v1.7.4, https://www.cve.org/CVERecord?id=CVE-2023-43643
Affected packages
Package
Name: libowasp-antisamy-java
Purl: pkg:deb/ubuntu/libowasp-antisamy-java?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
