CVE-2022-32533
06.07.2022, 10:15
Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dormant project of Apache Portals and no updates will be provided for this issue
Vendor | Product | Version |
---|---|---|
apache | jetspeed | 2.2.0 ≤ |
𝑥
= Vulnerable software versions
References