Security Advisory

CVE-2017-15717

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-01-10 14:00:00
Last updated 2024-09-17 01:06:14
Assigner apache
CVSS score not scored
State PUBLISHED

Description

A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they carry XSS payloads. The affected versions are Apache Sling XSS Protection API 1.0.4 to 1.0.18, Apache Sling XSS Protection API Compat 1.1.0 and Apache Sling XSS Protection API 2.0.0.