XSS Vulnerability in Apache Sling XSS Protection API
CVE-2017-15717

6.1MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
10 January 2018

Summary

A security flaw in the Apache Sling XSS Protection API allows specially crafted URLs to erroneously bypass validation checks. This vulnerability affects versions 1.0.4 through 1.0.18 of the API and enables malicious links containing XSS payloads to be treated as valid. Attackers can exploit this weakness to execute unauthorized scripts in the browser of unsuspecting users, compromising the integrity and security of web applications.

Affected Version(s)

Apache Sling XSS Protection API 1.0.4 to 1.0.18

Apache Sling XSS Protection API Compat 1.1.0

Apache Sling XSS Protection API 2.0.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.