CVE-2022-24891 Information

Description

ESAPI (The OWASP Enterprise Security API) is a free open source web application security control library. Prior to version 2.3.0.0 there is a potential for a cross-site scripting vulnerability in ESAPI caused by a incorrect regular expression for \onsiteURL\ in the antisamy-esapi.xml configuration file that can cause \javascript:\ URLs to fail to be correctly sanitized. This issue is patched in ESAPI 2.3.0.0. As a workaround manually edit the antisamy-esapi.xml configuration files to change the \onsiteURL\ regular expression. More information about remediation of the vulnerability including the workaround is available in the maintainers’ release notes and security bulletin.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

https://github.com/ESAPI/esapi-java-legacy/blob/develop/documentation/esapi4java-core-2.3.0.0-release-notes.txt https://github.com/ESAPI/esapi-java-legacy/security/advisories/GHSA-q77q-vx4q-xx6q https://github.com/ESAPI/esapi-java-legacy/blob/develop/documentation/ESAPI-security-bulletin8.pdf

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: