CVE-2021-42575

Description

The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.718

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-42575 are fixed in Google-owasp-java-html-sanitizer 20211018.1Windows
Multiple vulnerabilities are affected in Oracle Commerce Platform 11.3.0Windows
Multiple vulnerabilities are affected in Oracle Commerce Platform 11.3.1Windows
Multiple vulnerabilities are affected in Oracle Commerce Platform 11.3.2Windows
Vulnerabilities CVE-2021-42575 are fixed in Google-owasp-java-html-sanitizer for Linux 20211018.1Linux
CVE-2021-42575NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234