First published: Wed Jan 13 2021(Updated: )
OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbitrary HTML or XML into embedding documents.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OWASP Java HTML Sanitizer | <1.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23899 is a vulnerability in OWASP json-sanitizer before version 1.2.2 that allows an attacker to inject arbitrary HTML or XML into embedding documents.
CVE-2021-23899 is rated as critical with a severity value of 9.8.
OWASP json-sanitizer versions up to but excluding 1.2.2 are affected by CVE-2021-23899.
An attacker can exploit CVE-2021-23899 by providing crafted input that results in the emission of closing SCRIPT tags and CDATA section delimiters by the json-sanitizer library.
To fix CVE-2021-23899, update to version 1.2.2 or later of the OWASP json-sanitizer library.