First published: Mon Aug 31 2015(Updated: )
Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.jsoup:jsoup | >=1.6.0<=1.8.2 | 1.8.3 |
redhat/jsoup | <1.8.3 | 1.8.3 |
jsoup | <1.8.3 | |
jsoup | >=1.6.0<1.8.3 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6748 is classified as a medium severity cross-site scripting (XSS) vulnerability in jsoup before version 1.8.3.
To fix CVE-2015-6748, upgrade jsoup to version 1.8.3 or later.
CVE-2015-6748 affects all jsoup versions from 1.6.0 up to but not including 1.8.3.
Yes, CVE-2015-6748 is relevant to applications that use jsoup, such as JBoss EAP and WildFly.
CVE-2015-6748 is a cross-site scripting (XSS) vulnerability.