6.1
CVSSv3

CVE-2024-23635

Published: 02/02/2024 Updated: 10/02/2024
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. before 1.7.5, there is a potential for a mutation XSS (mXSS) vulnerability in AntiSamy caused by flawed parsing of the HTML being sanitized. To be subject to this vulnerability the `preserveComments` directive must be enabled in your policy file. As a result, certain crafty inputs can result in elements in comment tags being interpreted as executable when using AntiSamy's sanitized output. Patched in AntiSamy 1.7.5 and later.

Vulnerable Product Search on Vulmon Subscribe to Product

antisamy project antisamy

Vendor Advisories

Debian Bug report logs - #1062846 libowasp-antisamy-java: CVE-2024-23635 Package: src:libowasp-antisamy-java; Maintainer for src:libowasp-antisamy-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 3 Feb 2024 20:15:07 UTC S ...