AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to version 1.7.4, there is a potential for a mutation XSS (mXSS) vulnerability in AntiSamy caused by flawed parsing of the HTML being sanitized. To be subject to this vulnerability the `preserveComments` directive must be enabled in your policy file and also allow for certain tags at the same time. As a result, certain crafty inputs can result in elements in comment tags being interpreted as executable when using AntiSamy's sanitized output. This issue has been patched in AntiSamy 1.7.4 and later.
History

Thu, 19 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-10-09T13:31:46.324Z

Updated: 2024-09-19T13:57:25.721Z

Reserved: 2023-09-20T15:35:38.146Z

Link: CVE-2023-43643

cve-icon Vulnrichment

Updated: 2024-08-02T19:44:43.824Z

cve-icon NVD

Status : Analyzed

Published: 2023-10-09T14:15:10.797

Modified: 2023-10-13T17:35:04.310

Link: CVE-2023-43643

cve-icon Redhat

No data.