ZeroHour

CVE-2021-42575

PoC
CVSS 3.1
9.8 critical
EPSS
3%p87
Published
()
Modified
Description

The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.

Vendors
owasporacle
Products
java html sanitizer, middleware common libraries and tools, primavera unifier
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.