org.owasp.antisamy:antisamy@1.4.2 vulnerabilities
-
latest version
1.7.6
-
latest non vulnerable version
-
first published
14 years ago
-
latest version published
4 months ago
-
licenses detected
- [1.4.2,1.5.5)
-
package manager
Direct Vulnerabilities
Known vulnerabilities in the org.owasp.antisamy:antisamy package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
org.owasp.antisamy:antisamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to flawed parsing of HTML input in the How to fix Cross-site Scripting (XSS)? Upgrade |
[,1.7.5)
|
org.owasp.antisamy:antisamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) when the How to fix Cross-site Scripting (XSS)? Upgrade |
[,1.7.4)
|
org.owasp.antisamy:antisamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via How to fix Cross-site Scripting (XSS)? Upgrade |
[,1.6.7)
|
org.owasp.antisamy:antisamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via How to fix Cross-site Scripting (XSS)? Upgrade |
[,1.6.6)
|
org.owasp.antisamy:antisamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via HTML attributes when using the HTML output serializer (XHTML is not affected). When serializing results to HTML, URLs are not being encoded when they are on HTML attributes. This can lead to mistakes when validating values. How to fix Cross-site Scripting (XSS)? Upgrade |
[,1.6.4)
|
org.owasp.antisamy:antisamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via How to fix Cross-site Scripting (XSS)? Upgrade |
[,1.5.5)
|
org.owasp.antisamy:antisamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Affected versions of this package are vulnerable to Cross-site Scripting (XSS)
via HTML5 entities, as demonstrated by use of How to fix Cross-site Scripting (XSS)? Upgrade |
[,1.5.7)
|