Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36847
HistoryAug 30, 2022 - 7:07 a.m.

Cross-site Scripting (XSS)

2022-08-3007:07:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
42
jsoup
vulnerability
resolve function
cross-site scripting
safelist
preserverelativelinks
arbitrary javascript

0.001 Low

EPSS

Percentile

44.5%

jsoup is vulnerable to cross-site scripting. The vulnerability exists in resolve function in StringUtil.java because the jsoup cleaner is not properly sanitized when SafeList.preserveRelativeLinks is enabled which allows an attacker to inject and execute arbitrary javascript.