XSS Vulnerability in Apache Sling XSS Protection API
CVE-2017-15717
What is CVE-2017-15717?
A security flaw in the Apache Sling XSS Protection API allows specially crafted URLs to erroneously bypass validation checks. This vulnerability affects versions 1.0.4 through 1.0.18 of the API and enables malicious links containing XSS payloads to be treated as valid. Attackers can exploit this weakness to execute unauthorized scripts in the browser of unsuspecting users, compromising the integrity and security of web applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Sling XSS Protection API 1.0.4 to 1.0.18
Apache Sling XSS Protection API Compat 1.1.0
Apache Sling XSS Protection API 2.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved