CVE-2021-42575
Policies not properly enforced in OWASP Java HTML Sanitizer
Description
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT
, STYLE
, and OPTION
elements.
Base CVSS
9.8
EPSS Score
0.61%
Introduced Version
r136
Fix Available
20211018.2
Available Patches
Package
CVEs Fixed
Lines of Code Changed