CVE-2022-24891 Information
Description
ESAPI (The OWASP Enterprise Security API) is a free open source web application security control library. Prior to version 2.3.0.0 there is a potential for a cross-site scripting vulnerability in ESAPI caused by a incorrect regular expression for \onsiteURL\ in the antisamy-esapi.xml configuration file that can cause \javascript:\ URLs to fail to be correctly sanitized. This issue is patched in ESAPI 2.3.0.0. As a workaround manually edit the antisamy-esapi.xml configuration files to change the \onsiteURL\ regular expression. More information about remediation of the vulnerability including the workaround is available in the maintainers’ release notes and security bulletin.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
https://github.com/ESAPI/esapi-java-legacy/blob/develop/documentation/esapi4java-core-2.3.0.0-release-notes.txt https://github.com/ESAPI/esapi-java-legacy/security/advisories/GHSA-q77q-vx4q-xx6q https://github.com/ESAPI/esapi-java-legacy/blob/develop/documentation/ESAPI-security-bulletin8.pdf
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: