CVE-2021-35043: XSS
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-35043?
CVE-2021-35043 is a vulnerability in OWASP AntiSamy before 1.6.4 that allows XSS via HTML attributes when using the HTML output serializer.
How does CVE-2021-35043 affect Antisamy Project Antisamy?
Antisamy Project Antisamy versions up to exclusive 1.6.4 are affected by CVE-2021-35043.
Which Oracle products are affected by CVE-2021-35043?
Oracle Retail Back Office versions 14.0 and 14.1, Oracle Retail Central Office versions 14.0 and 14.1, Oracle Retail Returns Management versions 14.0 and 14.1, Oracle Banking Enterprise Default Management versions 2.6.2, 2.7.0, 2.7.1, 2.10.0, and 2.12.0, Oracle Banking Enterprise Default Management versions between inclusive 2.3.0 and 2.4.0, Oracle Banking Party Management version 2.7.0, Oracle Banking Platform versions between inclusive 2.3.0 and 2.4.1, Oracle Insurance Policy Administration versions 11.0.2, 11.1.0, 11.2.8, 11.3.0, and 11.3.1, and Oracle Middleware Common Libraries And Tools versions 12.2.1.3.0 and 12.2.1.4.0 are affected by CVE-2021-35043.
What is the severity of CVE-2021-35043?
CVE-2021-35043 has a severity value of 6.1, which is categorized as medium.
How can I fix CVE-2021-35043?
To fix CVE-2021-35043, update to OWASP AntiSamy version 1.6.4 or newer.