org.apache.sling:org.apache.sling.xss.compat
Maven3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.sling:org.apache.sling.xss.compatpage 1 of 1
- CVE-2016-5394MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.1.02017-07-19
vulnerable: 1.0.0
In the XSS Protection API module before 1.0.12 in Apache Sling, the encoding done by the XSSAPI.encodeForJSString() method is not restrictive enough and for some input patterns allows script tags to pass through unencoded, leading to poten…
- CVE-2016-6798CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.1.02017-07-19
vulnerable: 1.0.0
In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts which use this method to validate user input…
- CVE-2017-15717MEDIUMCVSS 6.1EG 6.12018-01-10
vulnerable: 1.1.0
A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they carry XSS payloads.…
Check whether org.apache.sling:org.apache.sling.xss.compat is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.sling:org.apache.sling.xss.compat CVEs against the assets you own.
Start Free Scan →