First published: Mon Jul 19 2021(Updated: )
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Antisamy Project Antisamy | <1.6.4 | |
Oracle Retail Back Office | =14.0 | |
Oracle Retail Back Office | =14.1 | |
Oracle Retail Central Office | =14.0 | |
Oracle Retail Central Office | =14.1 | |
Oracle Retail Returns Management | =14.0 | |
Oracle Retail Returns Management | =14.1 | |
Oracle Banking Enterprise Default Management | =2.6.2 | |
Oracle Banking Enterprise Default Management | =2.7.0 | |
Oracle Banking Enterprise Default Management | =2.7.1 | |
Oracle Banking Enterprise Default Management | =2.10.0 | |
Oracle Banking Enterprise Default Management | =2.12.0 | |
Oracle Banking Enterprise Default Managment | >=2.3.0<=2.4.0 | |
Oracle Banking Party Management | =2.7.0 | |
Oracle Banking Platform | >=2.3.0<=2.4.1 | |
Oracle Banking Platform | =2.6.2 | |
Oracle Banking Platform | =2.7.0 | |
Oracle Banking Platform | =2.7.1 | |
Oracle Insurance Policy Administration | =11.0.2 | |
Oracle Insurance Policy Administration | =11.1.0 | |
Oracle Insurance Policy Administration | =11.2.8 | |
Oracle Insurance Policy Administration | =11.3.0 | |
Oracle Insurance Policy Administration | =11.3.1 | |
Oracle Middleware Common Libraries And Tools | =12.2.1.3.0 | |
Oracle Middleware Common Libraries And Tools | =12.2.1.4.0 | |
Netapp Active Iq Unified Manager Linux | ||
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Active Iq Unified Manager Windows | ||
maven/org.owasp.antisamy:antisamy | >=1.5.7<1.6.4 | 1.6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35043 is a vulnerability in OWASP AntiSamy before 1.6.4 that allows XSS via HTML attributes when using the HTML output serializer.
Antisamy Project Antisamy versions up to exclusive 1.6.4 are affected by CVE-2021-35043.
Oracle Retail Back Office versions 14.0 and 14.1, Oracle Retail Central Office versions 14.0 and 14.1, Oracle Retail Returns Management versions 14.0 and 14.1, Oracle Banking Enterprise Default Management versions 2.6.2, 2.7.0, 2.7.1, 2.10.0, and 2.12.0, Oracle Banking Enterprise Default Management versions between inclusive 2.3.0 and 2.4.0, Oracle Banking Party Management version 2.7.0, Oracle Banking Platform versions between inclusive 2.3.0 and 2.4.1, Oracle Insurance Policy Administration versions 11.0.2, 11.1.0, 11.2.8, 11.3.0, and 11.3.1, and Oracle Middleware Common Libraries And Tools versions 12.2.1.3.0 and 12.2.1.4.0 are affected by CVE-2021-35043.
CVE-2021-35043 has a severity value of 6.1, which is categorized as medium.
To fix CVE-2021-35043, update to OWASP AntiSamy version 1.6.4 or newer.