CVE-2022-24891
published 2022-04-27CVE-2022-24891: ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, there is a potential for…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.63%
73.7th percentile
ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, there is a potential for a cross-site scripting vulnerability in ESAPI caused by a incorrect regular expression for "onsiteURL" in the **antisamy-esapi.xml** configuration file that can cause "javascript:" URLs to fail to be correctly sanitized. This issue is patched in ESAPI 2.3.0.0. As a workaround, manually edit the **antisamy-esapi.xml** configuration files to change the "onsiteURL" regular expression. More information about remediation of the vulnerability, including the workaround, is available in the maintainers' release notes and security bulletin.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libowasp-esapi-java | < libowasp-esapi-java 2.4.0.0-1 (bookworm) | libowasp-esapi-java 2.4.0.0-1 (bookworm) |
| esapi | esapi-java-legacy | <= 2.2.3.1 | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| owasp | enterprise_security_api | < 2.3.0.0 | 2.3.0.0 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_ubuntu9.8CRITICAL
vendor_oracle6.1MEDIUM
vendor_debian5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Cross-site Scripting in org.owasp.esapi:esapi
osv·2022-04-27
CVE-2022-24891 [MEDIUM] Cross-site Scripting in org.owasp.esapi:esapi
Cross-site Scripting in org.owasp.esapi:esapi
### Impact
There is a potential for an XSS vulnerability in ESAPI caused by a incorrect regular expression for "onsiteURL" in the **antisamy-esapi.xml** configuration file that can cause URLs with the "javascript:" scheme to NOT be sanitized. See the reference below for full details.
### Patches
Patched in ESAPI 2.3.0.0 and later. See important remediation details in the reference given below.
### Workarounds
Manually edit your **antisamy-esapi.xml** configuration files to change the "onsiteURL" regular expression as per remediation instructions in the reference below.
### References
[Security Bulletin 8](https://github.com/ESAPI/esapi-java-legacy/blob/develop/documentation/ESAPI-security-bulletin8.pdf)
### For more information
If you have
GHSA
Cross-site Scripting in org.owasp.esapi:esapi
ghsa·2022-04-27
CVE-2022-24891 [MEDIUM] CWE-79 Cross-site Scripting in org.owasp.esapi:esapi
Cross-site Scripting in org.owasp.esapi:esapi
### Impact
There is a potential for an XSS vulnerability in ESAPI caused by a incorrect regular expression for "onsiteURL" in the **antisamy-esapi.xml** configuration file that can cause URLs with the "javascript:" scheme to NOT be sanitized. See the reference below for full details.
### Patches
Patched in ESAPI 2.3.0.0 and later. See important remediation details in the reference given below.
### Workarounds
Manually edit your **antisamy-esapi.xml** configuration files to change the "onsiteURL" regular expression as per remediation instructions in the reference below.
### References
[Security Bulletin 8](https://github.com/ESAPI/esapi-java-legacy/blob/develop/documentation/ESAPI-security-bulletin8.pdf)
### For more information
If you have
OSV
CVE-2022-24891: ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library
osv·2022-04-27·CVSS 6.1
CVE-2022-24891 [MEDIUM] CVE-2022-24891: ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library
ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, there is a potential for a cross-site scripting vulnerability in ESAPI caused by a incorrect regular expression for "onsiteURL" in the **antisamy-esapi.xml** configuration file that can cause "javascript:" URLs to fail to be correctly sanitized. This issue is patched in ESAPI 2.3.0.0. As a workaround, manually edit the **antisamy-esapi.xml** configuration files to change the "onsiteURL" regular expression. More information about remediation of the vulnerability, including the workaround, is available in the maintainers' release notes and security bulletin.
Ubuntu
ESAPI vulnerabilities
vendor_ubuntu·2026-04-16·CVSS 9.8
CVE-2025-5878 [CRITICAL] ESAPI vulnerabilities
Title: ESAPI vulnerabilities
Summary: Several security issues were fixed in ESAPI.
Jaroslav Lobačevski discovered that ESAPI incorrectly validated directory
paths during path verification. An attacker could possibly use this issue
to bypass directory validation checks, leading to control-flow bypass. This
issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
and Ubuntu 22.04 LTS. (CVE-2022-23457)
Kevin W. Wall and Sebastian Passaro discovered that ESAPI did not properly
sanitize javascript URLs because of an incorrect regular expression. An
attacker could possibly use this issue to perform a cross-site scripting
attack. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu
20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-24891)
Longlong Gong discovered that
Oracle
Oracle Oracle Analytics Risk Matrix: Security (Enterprise Security API) — CVE-2022-24891
vendor_oracle·2023-07-15·CVSS 6.1
CVE-2022-24891 [MEDIUM] Oracle Oracle Analytics Risk Matrix: Security (Enterprise Security API) — CVE-2022-24891
Oracle Oracle Analytics Risk Matrix: Security (Enterprise Security API) vulnerability
CVE: CVE-2022-24891
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Debian
CVE-2022-24891: libowasp-esapi-java - ESAPI (The OWASP Enterprise Security API) is a free, open source, web applicatio...
vendor_debian·2022·CVSS 5.4
CVE-2022-24891 [MEDIUM] CVE-2022-24891: libowasp-esapi-java - ESAPI (The OWASP Enterprise Security API) is a free, open source, web applicatio...
ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, there is a potential for a cross-site scripting vulnerability in ESAPI caused by a incorrect regular expression for "onsiteURL" in the **antisamy-esapi.xml** configuration file that can cause "javascript:" URLs to fail to be correctly sanitized. This issue is patched in ESAPI 2.3.0.0. As a workaround, manually edit the **antisamy-esapi.xml** configuration files to change the "onsiteURL" regular expression. More information about remediation of the vulnerability, including the workaround, is available in the maintainers' release notes and security bulletin.
Scope: local
bookworm: resolved (fixed in 2.4.0.0-1)
bullseye: resolved (fixed in 2.4.0.0-0+deb11u1)
fo
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/ESAPI/esapi-java-legacy/blob/develop/documentation/ESAPI-security-bulletin8.pdfhttps://github.com/ESAPI/esapi-java-legacy/blob/develop/documentation/esapi4java-core-2.3.0.0-release-notes.txthttps://github.com/ESAPI/esapi-java-legacy/security/advisories/GHSA-q77q-vx4q-xx6qhttps://security.netapp.com/advisory/ntap-20230127-0014/https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://github.com/ESAPI/esapi-java-legacy/blob/develop/documentation/ESAPI-security-bulletin8.pdfhttps://github.com/ESAPI/esapi-java-legacy/blob/develop/documentation/esapi4java-core-2.3.0.0-release-notes.txthttps://github.com/ESAPI/esapi-java-legacy/security/advisories/GHSA-q77q-vx4q-xx6qhttps://lists.debian.org/debian-lts-announce/2025/07/msg00010.htmlhttps://security.netapp.com/advisory/ntap-20230127-0014/https://www.oracle.com/security-alerts/cpujul2022.html
2022-04-27
Published