Apache

Sling Xss Protection Api

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 23.09.2026 09:37:49
  • Zuletzt bearbeitet 30.09.2026 16:12:41

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issu...

  • EPSS 0.21%
  • Veröffentlicht 23.09.2026 09:29:11
  • Zuletzt bearbeitet 30.09.2026 16:13:54

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issu...

  • EPSS 0.17%
  • Veröffentlicht 23.09.2026 09:23:22
  • Zuletzt bearbeitet 30.09.2026 16:11:12

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issu...

  • EPSS 0.17%
  • Veröffentlicht 23.09.2026 09:20:52
  • Zuletzt bearbeitet 30.09.2026 15:59:43

Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issu...

  • EPSS 0.17%
  • Veröffentlicht 23.09.2026 09:09:43
  • Zuletzt bearbeitet 30.09.2026 16:14:33

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior may allow an attacker to perform a reflected cross-site s...

  • EPSS 2.91%
  • Veröffentlicht 10.01.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:15:04

A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they carry XSS payloads. The affect...