cbcvebase.
CVE-2017-15717
published 2018-01-10

CVE-2017-15717: A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref…

medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they carry XSS payloads. The affected versions are Apache Sling XSS Protection API 1.0.4 to 1.0.18, Apache Sling XSS Protection API Compat 1.1.0 and Apache Sling XSS Protection API 2.0.0.

Affected

6 ranges
VendorProductVersion rangeFixed in
apachesling_xss_protection_api<= 1.0.18
apachesling_xss_protection_api
apachesling_xss_protection_api_compat
apache_software_foundationapache_sling
apache_software_foundationapache_sling
apache_software_foundationapache_sling