Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1xNzdxLXZ4NHEteHg2cc1BTg
Cross-site Scripting in org.owasp.esapi:esapi
Impact
There is a potential for an XSS vulnerability in ESAPI caused by a incorrect regular expression for "onsiteURL" in the antisamy-esapi.xml configuration file that can cause URLs with the "javascript:" scheme to NOT be sanitized. See the reference below for full details.
Patches
Patched in ESAPI 2.3.0.0 and later. See important remediation details in the reference given below.
Workarounds
Manually edit your antisamy-esapi.xml configuration files to change the "onsiteURL" regular expression as per remediation instructions in the reference below.
References
For more information
If you have any questions or comments about this advisory:
- Email one of the project co-leaders. See email addresses listed on the OWASP ESAPI wiki page, under "Leaders".
- Send email to one of the two ESAPI related Google Groups listed under Where to Find More Information on ESAPI on our README.md page.
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xNzdxLXZ4NHEteHg2cc1BTg
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 2 years ago
Updated: over 1 year ago
CVSS Score: 6.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Identifiers: GHSA-q77q-vx4q-xx6q, CVE-2022-24891
References:
- https://github.com/ESAPI/esapi-java-legacy/security/advisories/GHSA-q77q-vx4q-xx6q
- https://nvd.nist.gov/vuln/detail/CVE-2022-24891
- https://github.com/ESAPI/esapi-java-legacy/blob/develop/documentation/ESAPI-security-bulletin8.pdf
- https://github.com/ESAPI/esapi-java-legacy/blob/develop/documentation/esapi4java-core-2.3.0.0-release-notes.txt
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://security.netapp.com/advisory/ntap-20230127-0014/
- https://github.com/advisories/GHSA-q77q-vx4q-xx6q
Blast Radius: 19.3
Affected Packages
maven:org.owasp.esapi:esapi
Dependent packages: 106Dependent repositories: 1,483
Downloads:
Affected Version Ranges: <= 2.2.3.1
Fixed in: 2.3.0.0
All affected versions:
All unaffected versions: 2.0.1, 2.1.0