CVE-2021-35043
published 2021-07-19CVE-2021-35043: OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a…
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.51%
71.6th percentile
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| antisamy_project | antisamy | < 1.6.4 | 1.6.4 |
| debian | libowasp-antisamy-java | < libowasp-antisamy-java 1.7.4-1 (forky) | libowasp-antisamy-java 1.7.4-1 (forky) |
| oracle | banking_enterprise_default_management | — | — |
| oracle | banking_enterprise_default_management | — | — |
| oracle | banking_enterprise_default_management | — | — |
| oracle | banking_enterprise_default_management | — | — |
| oracle | banking_enterprise_default_management | — | — |
| oracle | banking_enterprise_default_managment | 2.3.0 – 2.4.0 | — |
| oracle | banking_party_management | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | 2.3.0 – 2.4.1 | — |
| oracle | insurance_policy_administration | — | — |
| oracle | insurance_policy_administration | — | — |
| oracle | insurance_policy_administration | — | — |
| oracle | insurance_policy_administration | — | — |
| oracle | insurance_policy_administration | — | — |
| oracle | middleware_common_libraries_and_tools | — | — |
| oracle | middleware_common_libraries_and_tools | — | — |
| oracle | retail_back_office | — | — |
| oracle | retail_back_office | — | — |
| oracle | retail_central_office | — | — |
| oracle | retail_central_office | — | — |
| oracle | retail_returns_management | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_oracle6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Cross-site Scripting in OWASP AntiSamy
osv·2021-08-02
CVE-2021-35043 [MEDIUM] Cross-site Scripting in OWASP AntiSamy
Cross-site Scripting in OWASP AntiSamy
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
GHSA
Cross-site Scripting in OWASP AntiSamy
ghsa·2021-08-02
CVE-2021-35043 [MEDIUM] CWE-79 Cross-site Scripting in OWASP AntiSamy
Cross-site Scripting in OWASP AntiSamy
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
OSV
CVE-2021-35043: OWASP AntiSamy before 1
osv·2021-07-19·CVSS 6.1
CVE-2021-35043 [MEDIUM] CVE-2021-35043: OWASP AntiSamy before 1
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
Oracle
Oracle Oracle Insurance Applications Risk Matrix: Logger (AntiSamy) — CVE-2021-35043
vendor_oracle·2023-04-15·CVSS 6.1
CVE-2021-35043 [MEDIUM] Oracle Oracle Insurance Applications Risk Matrix: Logger (AntiSamy) — CVE-2021-35043
Oracle Oracle Insurance Applications Risk Matrix: Logger (AntiSamy) vulnerability
CVE: CVE-2021-35043
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Insurance Applications Risk Matrix: Architecture (AntiSamy) — CVE-2021-35043
vendor_oracle·2022-04-15·CVSS 6.1
CVE-2021-35043 [MEDIUM] Oracle Oracle Insurance Applications Risk Matrix: Architecture (AntiSamy) — CVE-2021-35043
Oracle Oracle Insurance Applications Risk Matrix: Architecture (AntiSamy) vulnerability
CVE: CVE-2021-35043
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Collections (AntiSamy) — CVE-2021-35043
vendor_oracle·2022-01-15·CVSS 6.1
CVE-2021-35043 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Collections (AntiSamy) — CVE-2021-35043
Oracle Oracle Financial Services Applications Risk Matrix: Collections (AntiSamy) vulnerability
CVE: CVE-2021-35043
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Retail Applications Risk Matrix: Employee (AntiSamy) — CVE-2021-35043
vendor_oracle·2021-10-15·CVSS 6.1
CVE-2021-35043 [MEDIUM] Oracle Oracle Retail Applications Risk Matrix: Employee (AntiSamy) — CVE-2021-35043
Oracle Oracle Retail Applications Risk Matrix: Employee (AntiSamy) vulnerability
CVE: CVE-2021-35043
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Red Hat
AntiSamy: XSS via HTML attributes
vendor_redhat·2021-07-19·CVSS 6.1
CVE-2021-35043 [MEDIUM] CWE-79 AntiSamy: XSS via HTML attributes
AntiSamy: XSS via HTML attributes
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
A flaw was found in AnitSamy, where it allows a Cross-site Scripting attack (XSS) via HTML attributes when using the HTML output serializer (XHTML is not affected). This issue was demonstrated by a javascript: URL with : as the replacement for the : character. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Statement: Marking Red Hat JBoss Fuse 6 as having a low impact. Although AntiSamy is present in the offline repository, it is not used.
This vulnerability is out of security support
Debian
CVE-2021-35043: libowasp-antisamy-java - OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML o...
vendor_debian·2021·CVSS 6.1
CVE-2021-35043 [MEDIUM] CVE-2021-35043: libowasp-antisamy-java - OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML o...
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.7.4-1)
sid: resolved (fixed in 1.7.4-1)
trixie: resolved (fixed in 1.7.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/nahsra/antisamy/pull/87https://github.com/nahsra/antisamy/releases/tag/v1.6.4https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://github.com/nahsra/antisamy/pull/87https://github.com/nahsra/antisamy/releases/tag/v1.6.4https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-07-19
Published