CVE-2021-23900: High severity owasp java html sanitizer vulnerability
Published Jan 13, 2021
·Updated
OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input. This may lead to denial of service if the application is not prepared to handle these situations.
Affected Software
1 affected component
owasp json-sanitizer<1.2.2
Remediation
Event History
Jan 13, 2021
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the OWASP json-sanitizer issue?
The vulnerability ID is CVE-2021-23900.
2
What is the severity of CVE-2021-23900?
The severity of CVE-2021-23900 is high with a severity value of 7.5.
3
What is the affected software for CVE-2021-23900?
The affected software for CVE-2021-23900 is OWASP json-sanitizer before version 1.2.2.
4
What are the potential consequences of CVE-2021-23900?
The potential consequences of CVE-2021-23900 include outputting invalid JSON or throwing undeclared exceptions for crafted input, which may lead to denial of service if the application is not prepared to handle these situations.
5
How can I fix CVE-2021-23900?
To fix CVE-2021-23900, update OWASP json-sanitizer to version 1.2.2 or later.