CVE-2021-42575
Policies not properly enforced in OWASP Java HTML Sanitizer
Description
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
Base CVSS
9.8
EPSS Score
0.72%
Introduced Version
r136,1.1,20150501.1,20160413.1,20170329.1
Fix Available
20211018.2
Available Patches
Package
CVEs Fixed
Lines of Code Changed