CVE-2021-42575: Critical severity owasp java html sanitizer vulnerability
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-42575.
What is the severity of CVE-2021-42575?
The severity of CVE-2021-42575 is critical with a CVSS score of 9.8.
Which elements does the OWASP Java HTML Sanitizer before 20211018.1 fail to enforce policies on?
The OWASP Java HTML Sanitizer before 20211018.1 fails to enforce policies on the SELECT, STYLE, and OPTION elements.
Which software is affected by CVE-2021-42575?
The OWASP Java HTML Sanitizer before 20211018.1 and Oracle Middleware Common Libraries And Tools versions 12.2.1.3.0 and 12.2.1.4.0, as well as Oracle Primavera Unifier versions 17.7 to 17.12, 18.8, 19.12, 20.12, and 21.12 are affected by CVE-2021-42575.
How do I fix CVE-2021-42575?
To fix CVE-2021-42575, update to the latest version of OWASP Java HTML Sanitizer (20211018.2) or Oracle Middleware Common Libraries And Tools (12.2.1.3.1 or later).