Lucene search

K
cvelistApacheCVELIST:CVE-2022-32533
HistoryJul 06, 2022 - 9:40 a.m.

CVE-2022-32533 Apache Portals Jetspeed XSS, CSRF, SSRF, and XXE issues

2022-07-0609:40:12
CWE-79
apache
www.cve.org

9.8 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.2%

Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option “xss.filter.post = true” may mitigate these issues. NOTE: Apache Jetspeed is a dormant project of Apache Portals and no updates will be provided for this issue

CNA Affected

[
  {
    "product": "Apache Portals",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "Jetspeed 2.3.1"
      }
    ]
  }
]

9.8 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.2%

Related for CVELIST:CVE-2022-32533